THE  NATIONAL  STRATEGY  FOR 

The  Physical  Protect  ion 
of  C  r  it  ical  Inf  rast  ruct  ures 
and  Key  Asset  s 


february  2003 


REPORT  DOCUMENTATION  PAGE 


Form  Approved  OMB  No. 
0704-0188 

Public  reporting  burder  for  this  collection  of  information  is  estibated  to  average  1  hour  per  response,  including  the  time  for  reviewing  instructions,  searching  existing  data  sources,  gathering  and  maintaining  the  data  needed,  and  completing 
and  reviewing  this  collection  of  information.  Send  comments  regarding  this  burden  estimate  or  any  other  aspect  of  this  collection  of  information,  including  suggestions  for  reducing  this  burder  to  Department  of  Defense,  Washington 
Headquarters  Services,  Directorate  for  Information  Operations  and  Reports  (0704-0188),  1215  Jefferson  Davis  Highway,  Suite  1204,  Arlington,  VA  22202-4302.  Respondents  should  be  aware  that  notwithstanding  any  other  provision  of 
law,  no  person  shall  be  subject  to  any  penalty  for  failing  to  comply  with  a  collection  of  information  if  it  does  not  display  a  currently  valid  OMB  control  number.  PLEASE  DO  NOT  RETURN  YOUR  FORM  TO  THE  ABOVE  ADDRESS. 


1 .  REPORT  DATE  (DD-MM-YYYY)  2.  REPORT  TYPE  3.  DATES  COVERED  (FROM  -  TO) 

01-02-2003  xx-xx-2001  to  xx-xx-2002 

4.  TITLE  AND  SUBTITLE 

THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL 
INFRASTRUCTURES  AND  KEY  ASSETS 

Unclassified 

5a.  CONTRACT  NUMBER 

5b.  GRANT  NUMBER 

5c.  PROGRAM  ELEMENT  NUMBER 

6.  AUTHOR(S) 

BUSH,  GEORGE  W  ; 

5d.  PROJECT  NUMBER 

5e.  TASK  NUMBER 

5f.  WORK  UNIT  NUMBER 

7.  PERFORMING  ORGANIZATION  NAME  AND  ADDRESS 

THE  WHITE  HOUSE 

WASHINGTON,  DC22202 

8.  PERFORMING  ORGANIZATION  REPORT 
NUMBER 

9.  SPONSORING/MONITORING  AGENCY  NAME  AND  ADDRESS 

10.  SPONSOR/MONITOR’S  ACRONYM(S) 

11.  SPONSOR/MONITOR’S  REPORT 

NUMBER(S) 

12.  DISTRIBUTION/AVAILABILITY  STATEMENT 
APUBLIC  RELEASE 


13.  SUPPLEMENTARY  NOTES 

14.  ABSTRACT 

THIS  DOCUMENT  REPRESENTS  THE  FIRST  MILESTONE  IN  THE  ROAD  AHEAD.  CONSISTENT  WITH  THE  NATIONAL 
STRATEGY  FOR  HOMELAND  SECURITY,  THIS  DOCUMENT  IDENTIFIES  A  CLEAR  SET  OF  GOALS  AND  OBJECTIVES  AND 
OUTLINES  THE  GUIDING  PRINCIPLES  THAT  WILL  UNDERPIN  OUR  EFFORTS  TO  SECURE  THE  INFRASTRUCTURES  AND 
ASSETS  VITAL  TO  OUR  PUBLIC  HEALTH  AND  SAFETY,  NATIONAL  SECURITY,  GOVERNANCE,  ECONOMY,  AND  PUBLIC 
CONFIDENCE  SINCE  SEPTEMBER  1 1,  2001.  IT  PROVIDES  A  UNIFYING  STRUCTURE,  DEFINES  ROLES  AND 
RESPONSIBILITIES,  AND  IDENTIFIES  MAJOR  INITIATIVES  THAT  WILL  DRIVE  OUR  NEAR-TERM  PROTECTION  PRIORITIES. 
MOST  IMPORTANTLY,  IT  ESTABLISHES  A  FOUNDATION  FOR  BUILDING  AND  FOSTERING  A  COOPERATIVE 
ENVIRONMENT  IN  WHICH  GOVERNMENT,  INDUSTRY,  AND  PRIVATE  CITIZENS  CAN  WORK  TOGETHER  TO  PROTECT  OUR 
CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS. 

15.  SUBJECT  TERMS 

HOMELAND  SECURITY ;9 1 1  ;SEPTEMBER  11  PHYSICAL  PROTECTION;  TERRORISM;NATIONAL  POLICY;KEY 
ASSETS;SECURITY PERSONNEL  SECURITY;AWARENESS;AGRICULTURE;GOOD;WATER;PUBLIC  HEALTH;EMERGENCY 
SERVICES ;DEFENSE  INDUSTRIAL  BASE;TELECOMMUNICATIONS;ENERGY;TRANSPORTATION;BANKING  AND 
FINANCE;CHEMICAL  INDUSTRY ;HAZARDOUS  MATERIALS ;POSTAL  AND  SHIPPING;NATIONAL 
MONUMENTS  ;ICONS;NUCLEAR  POWER  PLANTS  ;D  AMS  COMMERCIAL  ASSETS 


11 6.  SECURITY  CLASSIFICATION  OF:  1 

17.  LIMITATION 

18. 

19.  NAME  OF  RESPONSIBLE  PERSON 

OF  ABSTRACT 

NUMBER 

EGNER,  DONNA 

Same  as  Report 
(SAR) 

OF  PAGES 
83 

DEGNER@BAH.COM 

a.  REPORT 

b.  ABSTRACT 

c.  THIS  PAGE 

19b.  TELEPHONE  NUMBER 

Unclassified 

Unclassified 

Unclassified 

International  Area  Code 

Area  Code  Telephone  Number 

937255-3828 

DSN 

785-3828 

Standard  Form  298  (Rev.  8-98) 
Prescribed  by  ANSI  Std  Z39.18 


THE  NATIONAL  STRATEGY  FOR 

The  Physical  Prot ect  ion 
of  C r it ical  Inf rast ruct ures 
and  Key  Asset  s 


february  2003 


the  white  house 
Washington 


M  y  Fellow  A  mericans: 

T  he  September  11,  2001,  attacks  demonstrated  the  extent  of  our  vulnerability  to  the  terrorist  threat. 

I  n  the  aftermath  of  these  tragic  events,  we,  as  a  N  ation,  have  demonstrated  firm  resolve  in  protecting  our 
critical  infrastructures  and  key  assets  from  further  terrorist  exploitation.  I  n  this  effort,  government  at  all 
levels,  the  private  sector,  and  concerned  citizens  across  the  country  have  begun  an  important  partnership 
and  commitment  to  action. 

To  address  the  threat  posed  by  those  who  wish  to  harm  the  United  States,  critical  infrastructure  owners 
and  operators  are  assessing  their  vulnerabilities  and  increasing  their  investment  in  security.  State  and 
municipal  governments  across  the  country  continue  to  take  important  steps  to  identify  and  assure  the 
protection  of  key  assets  and  services  within  their  jurisdictions.  Federal  departments  and  agencies  are 
working  closely  with  industry  to  take  stock  of  key  assets  and  facilitate  protective  actions,  while  improving 
the  timely  exchange  of  important  security- related  information.  The  Office  of  FI  omeland  Security  is 
working  closely  with  key  public-  and  private- sector  entities  to  implement  the  H  omeland  Security 
Advisory  System  across  all  levels  of  government  and  the  critical  sectors.  F  inally,  I  commend  the  M  embers 
of  C  ongress  for  working  diligently  to  pass  comprehensive  legislation  that  will  unify  our  national  critical 
infrastructure  and  key  asset  protection  efforts  in  the  new  D  epartment  of  H  omeland  Security. 

M  uch  work  remains,  however,  to  insure  that  we  sustain  these  initial  efforts  over  the  long  term.  This  N  ational 
Strategy  for  the  Physical  Protection  of  Critical  Infrastructures  and  Key  Assets  represents  the  first  milestone  in 
the  road  ahead.  Consistent  with  the  N  ational  Strategy  for  H  omeland  Security,  this  document  identifies  a  clear 
set  of  goals  and  objectives  and  outlines  the  guiding  principles  that  will  underpin  our  efforts  to  secure  the 
infrastructures  and  assets  vital  to  our  public  health  and  safety,  national  security,  governance,  economy,  and 
public  confidence.  It  provides  a  unifying  structure,  defines  roles  and  responsibilities,  and  identifies  major 
initiatives  that  will  drive  our  near-term  protection  priorities.  M  ost  importantly,  it  establishes  a  foundation 
for  building  and  fostering  a  cooperative  environment  in  which  government,  industry,  and  private  citizens 
can  work  together  to  protect  our  critical  infrastructures  and  key  assets. 


T  he  N  ational  Strategy  for  the  Physical  Protection  of  Critical  Infrastructures  and  Key  Assets  is  the  product 
of  many  months  of  consultation  across  a  broad  range  of  public-  and  private- sector  stakeholders. 

It  includes  extensive  input  from  the  federal  departments  and  agencies,  state  and  municipal  government, 
private- sector  infrastructure  owners  and  operators,  the  scientific  and  technology  community,  professional 
associations,  research  institutes,  and  concerned  citizens  across  the  country.  This  document  is  a  truly 
national  strategy. 

As  we  work  to  implement  this  Strategy,  it  is  important  to  remember  that  protection  of  our  critical 
infrastructures  and  key  assets  is  a  shared  responsibility.  Accordingly,  the  success  of  our  protective  efforts 
will  require  close  cooperation  between  government  and  the  private  sector  at  all  levels.  E  ach  of  us  has 
an  extremely  important  role  to  play  in  protecting  the  infrastructures  and  assets  that  are  the  basis  for  our 
daily  lives  and  that  represent  important  components  of  our  national  power  and  prestige. 

The  terrorist  enemy  that  we  face  is  highly  determined,  patient,  and  adaptive.  In  confronting  this  threat, 
protecting  our  critical  infrastructures  and  key  assets  represents  an  enormous  challenge.  W e  must 
remain  united  in  our  resolve,  tenacious  in  our  approach,  and  harmonious  in  our  actions  to  overcome 
this  challenge  and  secure  the  foundations  of  our  Nation  and  way  of  life. 


TABLE  OF  CONTENTS 


Executive  Summary . vii 

Introduction . 1 

The  Case  for  Action . 5 

N  ational  Policy  and  G  uiding  Principles . 11 

0  rganizing  and  Partnering  for  C  ritical  I  nfrastructure  and  Key  Asset  Protection . 15 

C  ross- Sector  Security  Priorities . 21 

Planning  and  Resource  Allocation . 22 

Information  Sharing  and  Indications  and  Warnings . 25 

Personnel  Surety,  Building  H  uman  Capital,  and  Awareness . 28 

Technology  and  Research  &  Development . 31 

M  odeling,  Simulation,  and  Analysis . 33 

Securing  Critical  Infrastructures . 35 

Agriculture  and  Food . 36 

Water . 39 

Public  H  ealth . 41 

E  mergency  Services . 43 

Defense  I  ndustrial  Base . 45 

T  elecommunications . 47 

E  nergy . 50 

Transportation . 54 

Banking  and  Finance . 63 

C  hemical  I  ndustry  and  H  azardous  M  aterials . 65 

Postal  and  Shipping . 67 

P  rotecti  ng  K  ey  A  ssets . 71 

National  Monuments  and  Icons . 72 

N  uclear  Power  Plants . 74 

Dams . 76 

Government  Facilities . 77 

Commercial  Key  A  ssets . 78 

Conclusion . 81 

Acronyms . 83 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  V 


Vi  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


EXECUTIVE  SUMMARY 


T  his  document  defines  the  road  ahead  for  a  core 
mission  area  identified  in  the  President’s  N ational 
Strategy  for  H  omeland  Security—  reducing  the  N  ation's 
vulnerability  to  acts  of  terrorism  by  protecting  our  crit¬ 
ical  infrastructures  and  key  assets  from  physical  attack. 

T  his  document,  the  N  ational  Strategy  for  the  Physical 
Protection  of  Critical  Infrastructures  and  Key  Assets,  the 
Strategy,  identifies  a  clear  set  of  national  goals  and 
objectives  and  outlines  the  guiding  principles  that  will 
underpin  our  efforts  to  secure  the  infrastructures  and 
assets  vital  to  our  national  security,  governance,  public 
health  and  safety,  economy,  and  public  confidence. This 
Strategy  also  provides  a  unifying  organization  and 
identifies  specific  initiatives  to  drive  our  near-term 
national  protection  priorities  and  inform  the  resource 
allocation  process.  M  ost  importantly,  it  establishes  a 
foundation  for  building  and  fostering  the  cooperative 
environment  in  which  government,  industry,  and 
private  citizens  can  carry  out  their  respective  protection 
responsibilities  more  effectively  and  efficiently. 

T  his  Strategy  recognizes  the  many  important  steps  that 
public  and  private  entities  across  the  country  have 
taken  in  response  to  the  September  11,  2001,  attacks  to 
improve  the  security  of  their  critical  facilities,  systems, 
and  functions.  Building  upon  these  efforts,  this  docu¬ 
ment  provides  direction  to  the  federal  departments  and 
agencies  that  have  a  role  in  critical  infrastructure  and 
key  asset  protection.  It  also  suggests  steps  that  state 
and  local  governments,  private  sector  entities,  and 
concerned  citizens  across  A  merica  can  take  to  enhance 
our  collective  infrastructure  and  asset  security.  I  n  this 
light,  this  Strategy  belongs  and  applies  to  the  N  ation  as 
a  whole,  not  just  to  the  federal  government  or  its 
constituent  departments  and  agencies. 

A  N  ew  M  ission 

T  he  September  11  attacks  demonstrated  our  national- 
level  physical  vulnerability  to  the  threat  posed  by  a 
formidable  enemy- focused,  mass  destruction  terrorism. 
T  he  events  of  that  day  also  validated  how  determined, 
patient,  and  sophisticated— in  both  planning  and 
execution—  our  terrorist  enemies  have  become.  T  he 
basic  nature  of  our  free  society  greatly  enables  terrorist 
operations  and  tactics,  while,  at  the  same  time,  hinders 
our  ability  to  predict,  prevent,  or  mitigate  the  effects  of 


terrorist  acts.  G  iven  these  realities,  it  is  imperative 
to  develop  a  comprehensive  national  approach  to 
physical  protection. 

D  efining  the  E  nd  State:  Strategic  0  bjectives 

The  strategic  objectives  that  underpin  our  national 
critical  infrastructure  and  key  asset  protection 
effort  include: 

•  Identifying  and  assuring  the  protection  of  those 
infrastructures  and  assets  that  we  deem  most  critical 
in  terms  of  national- level  public  health  and  safety, 
governance,  economic  and  national  security,  and 
public  confidence  consequences; 

•  Providing  timely  warning  and  assuring  the  protec¬ 
tion  of  those  infrastructures  and  assets  that  face  a 
specific,  imminent  threat;  and 

•  Assuring  the  protection  of  other  infrastructures  and 
assets  that  may  become  terrorist  targets  over  time  by 
pursuing  specific  initiatives  and  enabling  a  collabo¬ 
rative  environment  in  which  federal,  state,  and  local 
governments  and  the  private  sector  can  better 
protect  the  infrastructures  and  assets  they  control. 

H  omeland  Security  and  I  nfrastructure 
Protection:  A  Shared  Responsibility 

Protecting  America’s  critical  infrastructures  and  key 
assets  calls  for  a  transition  to  a  new  national  coopera¬ 
tive  paradigm.  T  he  basic  tenets  of  homeland  security  are 
fundamentally  different  from  the  historically  defined 
tenets  of  national  security.  T raditionally,  national 
security  has  been  recognized  largely  as  the  responsibility 
of  the  federal  government.  N  ational  security  is  under- 
pinned  by  the  collective  efforts  of  the  military,  foreign 
policy  establishment,  and  intelligence  community 
in  the  defense  of  our  airspace  and  national  borders, 
as  well  as  operations  overseas  to  protect  our 
national  interests. 

H  omeland  security,  particularly  in  the  context  of  critical 
infrastructure  and  key  asset  protection,  is  a  shared 
responsibility  that  cannot  be  accomplished  by  the 
federal  government  alone.  It  requires  coordinated 
action  on  the  part  of  federal,  state,  and  local  govern¬ 
ments;  the  private  sector;  and  concerned  citizens  across 
the  country.1 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  VN 


THE  CASE  FOR  ACTION 

T o  build  and  implement  a  robust  strategy  to  protect 
our  critical  infrastructures  and  key  assets  from  further 
terrorist  exploitation,  we  must  understand  the  motiva¬ 
tions  of  our  enemies  as  well  as  their  preferred  tactics 
and  targets.  We  must  complement  this  understanding 
with  a  comprehensive  assessment  of  the  infrastructures 
and  assets  to  be  protected,  their  vulnerabilities,  and  the 
challenges  associated  with  eliminating  or  mitigating 
those  vulnerabilities— a  task  that  will  require  the 
concerted  efforts  of  our  entire  l\l  ation. 

T  he  I  mportance  of  C  ritical  I  nfrastructures 

A  merica's  critical  infrastructure  sectors  provide  the 
foundation  for  our  national  security,  governance, 
economic  vitality,  and  way  of  life.  Furthermore,  their 
continued  reliability,  robustness,  and  resiliency  create  a 
sense  of  confidence  and  form  an  important  part  of  our 
national  identity  and  purpose.  Critical  infrastructures 
frame  our  daily  lives  and  enable  us  to  enjoy  one  of  the 
highest  overall  standards  of  living  in  the  world. 

The  facilities,  systems,  and  functions  that  comprise  our 
critical  infrastructures  are  highly  sophisticated  and 
complex.  They  include  human  assets  and  physical  and 
cyber  systems  that  work  together  in  processes  that  are 
highly  interdependent.  They  also  consist  of  key  nodes 
that,  in  turn,  are  essential  to  the  operation  of  the 
critical  infrastructures  in  which  they  function. 

T  he  I  mportance  of  Key  A  ssets 

Key  assets  and  high  profile  events  are  individual  targets 
whose  attack—  in  the  worst-case  scenarios— could 
result  in  not  only  large-scale  human  casualties  and 
property  destruction,  but  also  profound  damage  to  our 
national  prestige,  morale,  and  confidence. 

Individually,  key  assets  like  nuclear  power  plants  and 
dams  may  not  be  vital  to  the  continuity  of  critical  serv¬ 
ices  at  the  national  level.  H  owever,  a  successful  strike 
against  such  targets  may  result  in  a  significant  loss  of 
life  and  property  in  addition  to  long-term,  adverse 
public  health  and  safety  consequences.  Other  key  assets 
are  symbolically  equated  with  traditional  American 
values  and  institutions  or  U.S.  political  and  economic 
power.  0  ur  national  icons,  monuments,  and  historical 
attractions  preserve  history,  honor  achievements,  and 
represent  the  natural  grandeur  of  our  country.  T  hey 
celebrate  our  A  merican  ideals  and  way  of  life  and 
present  attractive  targets  for  terrorists,  particularly  when 
coupled  with  high  profile  events  and  celebratory  activi¬ 
ties  that  bring  together  significant  numbers  of  people. 


U  nderstanding  theT  hreat 

C  haracteri sties  of  Terrorism 

T  he  September  11  attacks  on  the  W  orld  T rade  C  enter 
and  the  Pentagon  underscore  the  determination  of  our 
terrorist  enemies.  T errorists  are  relentless  and  patient, 
as  evidenced  by  their  persistent  targeting  of  theWorld 
T rade  C  enter  towers  over  the  years.  T errorists  are  also 
opportunistic  and  flexible. They  learn  from  experience 
and  modify  their  tactics  and  targets  to  exploit  perceived 
vulnerabilities  and  avoid  observed  strengths.  As  secu¬ 
rity  increases  around  more  predictable  targets,  they 
shift  their  focus  to  less  protected  assets.  E  nhancing 
countermeasures  for  any  one  terrorist  tactic  or  target, 
therefore,  makes  it  more  likely  that  terrorists  will 
favor  another. 

T  he  N  ature  of  Possible  Attacks 

T errorists’  pursuit  of  their  long-term  strategic  objec¬ 
tives  includes  attacks  on  critical  infrastructures  and  key 
assets.  T errorists  target  critical  infrastructures  to 
achieve  three  general  types  of  effects: 

•  D  /red  infrastrudureeffeds  C  ascading  disruption  or 
arrest  of  the  functions  of  critical  infrastructures  or 
key  assets  through  direct  attacks  on  a  critical  node, 
system,  or  function. 

•  Indired  infrastrudureeffeds  C  ascading  disruption 
and  financial  consequences  for  government,  society, 
and  economy  through  public-  and  private- sector 
reactions  to  an  attack. 

•  E xptoitation  of  infrastrudure  E  xploitation  of 
elements  of  a  particular  infrastructure  to  disrupt  or 
destroy  another  target. 

NATIONAL  POLICY  AND 
GUIDING  PRINCIPLES 

This  Strategy  reaffirms  our  longstanding  national 
policy  regarding  critical  infrastructure  and  key  asset 
protection.  It  also  delineates  a  set  of  guiding  principles 
that  will  underpin  our  domestic  protection  strategy. 

Statement  of  N  ational  Policy 

Asa  Nation  we  remain  committed  to  protecting  our 
critical  infrastructures  and  key  assets  from  acts  of 
terrorism  that  would: 

•  I  mpair  the  federal  government’s  ability  to  perform 
essential  national  and  homeland  security  missions 
and  ensure  the  general  public’s  health  and  safety; 

•  U  ndermine  state  and  local  government  capacities  to 
maintain  order  and  to  deliver  minimum  essential 
public  services; 


viii  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


•  D  amage  the  private  sector’s  capability  to  ensure  the 
orderly  functioning  of  the  economy  and  the  delivery 
of  essential  services;  and 

•  U  ndermine  the  public's  morale  and  confidence  in 
our  national  economic  and  political  institutions. 

We  must  work  col laborati vely  to  employ  the  tools 
necessary  to  implement  such  protection. 

G  uiding  Principles 

Eight  guiding  principles  underpin  this  Strategy: 

•  Assure  public  safety,  public  confidence,  and  services; 

•  Establish  responsibility  and  accountability; 

•  E  ncourage  and  facilitate  partnering  among  all 
levels  of  government  and  between  government 
and  industry; 

•  E  ncourage  market  solutions  wherever  possible 
and  compensate  for  market  failure  with  focused 
government  intervention; 

•  Facilitate  meaningful  information  sharing; 

•  Foster  international  cooperation; 

•  D  evelop  technologies  and  expertise  to  combat 
terrorist  threats;  and 

•  Safeguard  privacy  and  constitutional  freedoms. 

ORGANIZING  AND 
PARTNERING  FOR  CRITICAL 
INFRASTRUCTURE  AND 
KEY  ASSET  PROTECTION 

Implementing  this  Strategy  requires  a  unifying  organi¬ 
zation,  a  clear  purpose,  a  common  understanding  of 
roles  and  responsibilities,  accountability,  and  a  set  of 
well- understood  coordinating  processes.  A  solid 
organizational  scheme  sets  the  stage  for  effective 
engagement  and  interaction  between  the  public  and 
private  sectors  at  all  levels.  W  ithout  it,  the  tasks  of 
coordinating  and  integrating  domestic  protection 
policy,  planning,  resource  allocation,  performance 
measurement,  and  enabling  initiatives  across  federal, 
state,  and  local  governments  and  the  private  sector  are 
virtually  impossible  to  accomplish.  0  ur  strategy  for 
action  must  provide  the  foundation  these  entities  can 
use  to  achieve  common  objectives,  applying  their  core 
capabilities,  expertise,  and  experience  as  necessary  to 
meet  the  threat  at  hand. 

Federal  G  overnment  Responsibilities 

T  he  federal  government  has  the  capacity  to  organize, 
convene,  and  coordinate  broadly  across  governmental 


jurisdictions  and  the  private  sector.  It  has  the  responsi¬ 
bility  to  develop  coherent  national  policies,  strategies, 
and  programs  for  implementation.  I  n  the  context  of 
homeland  security,  the  federal  government  will  coordi¬ 
nate  the  complementary  efforts  and  capabilities  of 
government  and  private  institutions  to  raise  our  level 
of  protection  over  the  long  term  as  appropriate  for  each 
of  our  critical  infrastructures  and  key  assets. 

E  very  terrorist  event  has  a  potential  national  impact. 

T  he  federal  government  will,  therefore,  take  the  lead 
to  ensure  that  the  three  principal  objectives  detailed 
in  the  Introduction  of  this  Strategy  are  met.  T  his 
leadership  role  involves: 

•  T aking  stock  of  our  most  critical  facilities,  systems, 
and  functions  and  monitoring  their  preparedness 
across  economic  sectors  and  governmental 
jurisdictions; 

•  Assuring  that  federal,  state,  local,  and  private 
entities  work  together  to  protect  critical  facilities, 
systems,  and  functions  that  face  an  imminent  threat 
and/or  whose  loss  could  have  significant  national 
consequences; 

•  Providing  and  coordinating  national- level  threat 
information,  assessments,  and  warnings  that  are 
timely,  actionable,  and  relevant  to  state,  local,  and 
private  sector  partners; 

•  C  reating  and  implementing  comprehensive, 
multi-tiered  protection  policies  and  programs; 

•  Exploring  potential  options  for  enablers  and 
incentives  to  encourage  stakeholders  to  devise 
solutions  to  their  unique  protection  impediments; 

•  D  eveloping  cross-sector  and  cross-jurisdictional 
protection  standards,  guidelines,  criteria,  and 
protocols; 

•  Facilitating  the  sharing  of  critical  infrastructure  and 
key  asset  protection  best  practices  and  processes  and 
vulnerability  assessment  methodologies; 

•  Conducting  demonstration  projects  and  pilot 
programs; 

•  Seeding  the  development  and  transfer  of  advanced 
technologies  while  taking  advantage  of  private- 
sector  expertise  and  competencies; 

•  Promoting  national- level  critical  infrastructure  and 
key  asset  protection  education  and  awareness;  and 

•  I  mproving  the  federal  government’s  ability  to 
work  with  state  and  local  responders  and 
service  providers. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  ix 


Federal  L  ead  D  epartments and  Agencies 

T  he  N ational  Strategy  for  H  omeland  Security  provides  a 
sector-based  organizational  scheme  for  protecting 
critical  infrastructure  and  key  assets.  It  identifies  the 
federal  lead  departments  and  agencies  responsible  for 
coordinating  protection  activities  and  developing  and 
maintaining  collaborative  relationships  with  their  state 
and  local  government  and  industry  counterparts  in  the 
critical  sectors. 

In  addition  to  securing  federally  owned  and  operated 
infrastructures  and  assets,  the  role  of  the  federal  lead 
departments  and  agencies  is  to  assist  state  and  local 
governments  and  private- sector  partners  in  their 
efforts  to: 

•  0  rganize  and  conduct  protection  and  continuity  of 
government  and  operations  planning,  and  elevate 
awareness  and  understanding  of  threats  and 
vulnerabilities  to  their  critical  facilities,  systems, 
and  functions; 

•  I  dentify  and  promote  effective  sector- specific 
protection  practices  and  methodologies;  and 

•  E  xpand  voluntary  security- related  information 
sharing  among  private  entities  within  the  sector,  as 
well  as  between  government  and  private  entities. 

D  epartment  of  H  omeland  Security 

T  he  D  epartment  of  H  omeland  Security  (D  H  S)  will 
provide  overall  cross- sector  coordination  in  this  new 
organizational  scheme,  serving  as  the  primary  liaison 
and  facilitator  for  cooperation  among  federal  agencies, 
state  and  local  governments,  and  the  private  sector.  As 
the  cross- sector  coordinator,  D  H  S  will  also  be  respon¬ 
sible  for  the  detailed  refinement  and  implementation 
of  the  core  elements  of  this  Strategy. 

Other  Federal  D  epartments  and  Agencies 

Besides  the  designated  federal  lead  departments  and 
agencies,  the  federal  government  will  rely  on  the 
unique  expertise  of  other  departments  and  agencies  to 
enhance  the  physical  protection  dimension  of  home¬ 
land  security.  Additionally,  overall  sector  initiatives  will 
often  include  an  international  component  or  require¬ 
ment,  require  the  development  of  a  coordinated 
relationship  with  other  governments  or  agencies,  and 
entail  information  sharing  with  foreign  governments. 
Accordingly,  the  D  epartment  of  State  (D  oS)  will 
support  the  development  and  implementation  of  sector 
protection  initiatives  by  laying  the  groundwork  for 
bilateral  and  multilateral  infrastructure  protective 
agreements  with  our  international  allies. 


State  and  L  ocal  G  overnment  Responsibilities 

The  50  states,  4  territories,  and  87,000  local  jurisdic¬ 
tions  that  comprise  this  N  ation  have  an  important  and 
unique  role  to  play  in  the  protection  of  our  critical 
infrastructures  and  key  assets.  State  and  local  govern¬ 
ments,  like  the  federal  government,  should  identify  and 
secure  the  critical  infrastructures  and  key  assets  they 
own  and  operate  within  their  jurisdictions. 

States  should  also  engender  coordination  of  protective 
and  emergency  response  activities  and  resource  support 
among  local  jurisdictions  and  regions  in  close  collabo¬ 
ration  with  designated  federal  lead  departments  and 
agencies.  States  should  further  facilitate  coordinated 
planning  and  preparedness  for  critical  infrastructure 
and  key  asset  protection,  applying  unified  criteria  for 
determining  criticality,  prioritizing  protection  invest¬ 
ments,  and  exercising  preparedness  within  their 
jurisdictions.  States  should  also  act  as  conduits  for 
requests  for  federal  assistance  when  the  threat  at  hand 
exceeds  the  capabilities  of  local  jurisdictions  and 
private  entities  within  those  jurisdictions.  Finally, 
states  should  facilitate  the  exchange  of  relevant  security 
information  and  threat  alerts  down  to  the  local  level. 

State  and  local  governments  look  to  the  federal 
government  for  coordination,  support,  and  resources 
when  national  requirements  exceed  local  capabilities. 
Protecting  critical  infrastructures  and  key  assets  will 
require  a  close  and  extensive  cooperation  among  all 
three  levels  of  government.  D  FI  S,  in  particular,  is 
designed  to  provide  a  single  point  of  coordination  with 
state  and  local  governments  for  homeland  security 
issues,  including  the  critical  infrastructure  and  key  asset 
protection  mission  area.  Other  federal  lead  depart¬ 
ments  and  agencies  and  law  enforcement  organizations 
will  provide  support  as  needed  and  appropriate  for 
specific  critical  infrastructure  and  key  asset 
protection  requirements. 

Private  Sector  Responsibilities 

T  he  lion's  share  of  our  critical  infrastructures  and  key 
assets  are  owned  and  operated  by  the  private  sector. 

C  ustomarily,  private  sector  firms  prudently  engage  in 
risk  management  planning  and  invest  in  security  as  a 
necessary  function  of  business  operations  and  customer 
confidence.  M  oreover,  in  the  present  threat  environ¬ 
ment,  the  private  sector  generally  remains  the  first  line 
of  defense  for  its  own  facilities.  C  onsequently,  private- 
sector  owners  and  operators  should  reassess  and  adjust 
their  planning,  assurance,  and  investment  programs  to 
better  accommodate  the  increased  risk  presented  by 
deliberate  acts  of  violence.  Since  the  events  of 


X  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


September  11,  many  businesses  have  increased  their 
threshold  investments  and  undertaken  enhancements 
in  security  in  an  effort  to  meet  the  demands  of  the 
new  threat  environment. 

For  most  enterprises,  the  level  of  investment  in  security 
reflects  implicit  risk- versus- consequence  tradeoffs, 
which  are  based  on:  (1)  what  is  known  about  the  risk 
environment;  and  (2)  what  is  economically  justifiable 
and  sustainable  in  a  competitive  marketplace  or  in  an 
environment  of  limited  government  resources.  G  iven 
the  dynamic  nature  of  the  terrorist  threat  and  the 
severity  of  the  consequences  associated  with  many 
potential  attack  scenarios,  the  private  sector  naturally 
looks  to  the  government  for  better  information  to  help 
make  its  crucial  security  investment  decisions. 

Similarly,  the  private  sector  looks  to  the  government 
for  assistance  when  the  threat  at  hand  exceeds  an 
enterprise’s  capability  to  protect  itself  beyond  a  reason¬ 
able  level  of  additional  investment.  In  this  light,  the 
federal  government  will  collaborate  with  the  private 
sector  (and  state  and  local  governments)  to  assure  the 
protection  of  nationally  critical  infrastructures  and 
assets;  provide  timely  warning  and  assure  the  protec¬ 
tion  of  infrastructures  and  assets  that  face  a  specific, 
imminent  threat;  and  promote  an  environment  in 
which  the  private  sector  can  better  carry  out  its  specific 
protection  responsibilities. 

N  ear- term  R  oadmap:  C  ross-  Sector 
Security  Priorities 

The  issues  and  security  initiatives  outlined  in  the 
Cross-Sector  Security  P  riori ties  chapter  of  this  document 
represent  important,  near-term  national  priorities. 

T  hey  are  focused  on  impediments  to  physical  protec¬ 
tion  that  significantly  impact  multiple  sectors  of  our 
government,  society,  and  economy.  Potential  solutions 
to  the  problems  identified—  such  as  information 
sharing  and  threat  indications  and  warning— are  high- 
leverage  areas  that,  when  realized,  will  enhance  the 
N  ation’s  collective  ability  to  protect  critical  infrastruc¬ 
tures  and  key  assets  across  the  board.  A  ccordingly, 

D  FI  S  and  designated  federal  lead  departments  and 
agencies  will  prepare  detailed  implementation  plans  to 
support  the  activities  outlined  in  this  chapter. 

This  Strategy  identifies  major  cross- sector  initiatives  in 
five  areas: 

Planning  and  Resource  A  /location:  T  his  Strategy 
identifies  eight  major  initiatives  in  this  area. 

•  C  reate  collaborative  mechanisms  for  government- 
industry  critical  infrastructure  and  key  asset 
protection  planning; 


•  I  dentify  key  protection  priorities  and  develop 
appropriate  supporting  mechanisms  for  these 
priorities; 

•  Foster  increased  sharing  of  risk- management 
expertise  between  the  public  and  private  sectors; 

•  Identify  options  for  incentives  for  private 
organizations  that  proactively  implement 
enhanced  security  measures; 

•  C  oordinate  and  consolidate  federal  and  state 
protection  plans; 

•  E  stablish  a  task  force  to  review  legal  impediments 
to  reconstitution  and  recovery  in  the  aftermath 

of  an  attack  against  a  critical  infrastructure  or 
key  asset; 

•  D  evelop  an  integrated  critical  infrastructure  and 
key  asset  geospatial  database;  and 

•  Conduct  critical  infrastructure  protection  planning 
with  our  international  partners. 

I  n  formation  Sharing  and  I ndicationsand  Warnings; 

This  Strategy  identifies  six  major  initiatives  in  thisarea. 

•  D efine  protection-related  information  sharing 
requirements  and  establish  effective,  efficient 
information  sharing  processes; 

•  I  mplement  the  statutory  authorities  and  powers 
of  the  H  omdand  Security  Act  of  2002  to  protect 
security  and  proprietary  information  regarded  as 
sensitive  by  the  private  sector; 

•  Promote  the  development  and  operation  of  critical 
sector  I  nformation  Sharing  A  nalysis  C  enters; 

•  I  mprove  processes  for  domestic  threat  data 
collection,  analysis,  and  dissemination  to  state 
and  local  government  and  private  industry; 

•  Support  the  development  of  interoperable  secure 
communications  systems  for  state  and  local  govern¬ 
ments  and  designated  private  sector  entities;  and 

•  Complete  implementation  of  the  FI  omeland 
Security  Advisory  System. 

Personnel  Surety,  Building  H  uman  C apital,  and 

Awareness;  T  his  Strategy  identifies  six  major  initiatives 

in  this  area. 

•  Coordinate  the  development  of  national  standards 
for  personnel  surety; 

•  D  evelop  a  certification  program  for  background¬ 
screening  companies; 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  Xi 


•  Explore  establishment  of  a  certification  regime  or 
model  security  training  program  for  private 
security  officers; 

•  Identify  requirements  and  develop  programs  to 
protect  critical  personnel; 

•  Facilitate  the  sharing  of  public-  and  private- sector 
protection  expertise;  and 

•  D  evelop  and  implement  a  national  awareness 
program  for  critical  infrastructure  and  key 
asset  protection. 

T echnology  and  R  eseardi  &  D  evelopment:  This  Strategy 

identifies  four  major  initiatives  in  this  area. 

•  Coordinate  public-  and  private- sector  security 
research  and  development  activities; 

•  C  oordinate  interoperability  standards  to  ensure 
compatibility  of  communications  systems; 

•  E  xplore  methods  to  authenticate  and  verify 
personnel  identity;  and 

•  Improve  technical  surveillance,  monitoring  and 
detection  capabilities. 

M  odeling,  Simulation,  and AnalysisT  his  Strategy 

identifies  seven  major  initiatives  in  this  area. 

•  Enable  the  integration  of  modeling,  simulation, 
and  analysis  into  national  infrastructure  and  asset 
protection  planning  and  decision  support  activities; 

•  D  evelop  economic  models  of  near-  and  long-term 
effects  of  terrorist  attacks; 

•  D  evelop  critical  node/chokepoint  and 
interdependency  analysis  capabilities; 

•  M  odel  interdependencies  across  sectors  with  respect 
to  conflicts  between  sector  alert  and  warning 
procedures  and  actions; 

•  Conduct  integrated  risk  modeling  of  cyber  and 
physical  threats,  vulnerabilities,  and  consequences; 
and 

•  D  evelop  models  to  improve  information  integration. 

U  nique  Protection  A  reas 

I  n  addition  to  the  cross- sector  themes  addressed  in  this 

Strategy,  the  individual  critical  infrastructure  sectors 


and  special  categories  of  key  assets  have  unique  issues 
that  require  action.  T  hese  considerations  and  associated 
enabling  initiatives  are  discussed  in  the  last  two 
chapters  of  this  Strategy: 

Securing  Critical  Infrastructures  T  his  Strategy  identifies 
major  protection  initiatives  for  the  following  critical 
infrastructure  sectors: 

•  Agriculture  and  Food 

•  W  ater 

•  Public  FI  ealth 

•  E  mergency  Services 

•  D  efense  I ndustrial  Base 

•  Telecommunications 

•  E  nergy 

•  Transportation 

•  Banking  and  Finance 

•  C  hemicals  and  FI  azardous  M  aterials 

•  Postal  and  Shipping 

P  rotecting  Key  A  ssets  T  h  i  s  S  trategy  i  denti  fi  es 
major  protection  initiatives  for  the  following  key 
asset  categories: 

•  N ational  M  onuments and  Icons 

•  N  uclear  Power  Plants 

•  D  ams 

•  G  overnment  Facilities 

•  Commercial  Key  A  ssets 


1  T  he  N  ational  Strategy  for  H  ome/and  Security  defines  "State" 
to  mean  "any  state  of  the  U  nited  States,  the  D  istrict  of 
Columbia,  Puerto  Rico,  theVirgin  Islands,  G  uam,  American 
Samoa,  the  C  ommonwealth  of  the  N  orthern  M  ariana 
Islands,  or  the  trust  territory  of  the  Pacific  Islands.  "The 
Strategy  defines  "local  government"  as  "any  county,  city, 
village,  town,  district,  or  other  political  subdivision  of  any 
state,  any  N  ative  American  tribe  or  authorized  tribal  organi¬ 
zation,  or  Alaska  native  village  or  organization,  and  includes 
any  rural  community  or  unincorporated  town  or  village  or 
any  other  public  entity  for  which  and  application  for 
assistance  is  made  by  a  state  or  political  subdivision  thereof." 


Xii  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


INTRODUCTION 


On  July  16,  2002,  President  Bush  issued  the N ational 
Strategy  for  H  omeland  Security,  an  overarching  strategy 
for  mobilizing  and  organizing  our  Nation  to  secure  the 
U.S.  homeland  from  terrorist  attacks.  It  communicates 
a  comprehensive  approach  "based  on  the  principles  of 
shared  responsibility  and  partnership  with  Congress, 
state  and  local  governments,  the  private  sector,  and  the 
A  merican  people"—  a  truly  national  effort,  not  merely 
a  federal  one. 

The  National  Strategy  for  H  ome/and  Security  defines 
"homeland  security"  and  identifies  a  strategic 
framework  based  on  three  national  objectives.  I  n  order 
of  priority,  these  are:  (1)  preventing  terrorist  attacks 
within  the  United  States,  (2)  reducing  America’s 
vulnerability  to  terrorism,  and  (3)  minimizing  the 
damage  and  recovering  from  attacks  that 
do  occur. 


HOMELAND  SECURITY 
CRITICAL  MISSION  AREAS 

I  intelligence  and  W  arning 
Border  and  T ransportation  Security 
D  omestic  C  ounter- terrorism 

Protecting  C  ritical  I  nfrastructuresand 
Key  Assets 

D  efending  against  C  atastrophic  T  errorism 
E  mergency  Preparedness  and  Response 


T o  attain  these  objectives,  the  National  Strategy  for 
H  omeland  Security  aligns  our  homeland  security  efforts 
into  six  critical  mission  areas:  intelligence  and  warning, 
border  and  transportation  security,  domestic  counter¬ 
terrorism,  protecting  critical  infrastructures  and  key 
assets,  defending  against  catastrophic  terrorism,  and 
emergency  preparedness  and  response. 

T  his  document,  the  N  ational  Strategy  for  thePhysical 
Protection  of  Critical  I  nfrastructures  and  K  ey  Assets,  the 
Strategy,1  takes  the  next  step  to  facilitate  the  strategic 
planning  process  for  a  core  mission  area  identified  in 


T  he  U  nited  States  will  forge  an 
unprecedented  level  of  cooperation 
throughout  all  levels  of  government, 
with  private  industry  and  institutions 
and  with  the  A  merican  people  to 
protect  our  critical  infrastructure 
and  key  assets  from  terrorist  attack. " 

■TheN  ational  Strategy  for  H  omeland  Security 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  1 


the  National  Strategy  for  H  omel and  Security—  reducing 
the  N  ation's  vulnerability  by  protecting  our  critical 
infrastructures  and  key  assets  from  physical  attack.  It 
identifies  a  clear  set  of  national  goals  and  objectives 
and  outlines  the  guiding  principles  that  will  underpin 
our  efforts  to  secure  the  infrastructures  and  assets  vital 
to  our  national  security,  governance,  public  health  and 
safety,  economy,  and  public  confidence.  It  also  provides 
a  unifying  organizational  structure  and  identifies 
specific  initiatives  to  drive  our  near-term  national 
protection  priorities  and  inform  the  resource  allocation 
process.  M  ost  importantly,  it  provides  a  foundation  for 
building  and  fostering  the  cooperative  environment  in 
which  government,  industry,  and  private  citizens  can 
carry  out  their  respective  protection  responsibilities 
more  effectively  and  efficiently. 

T  his  Strategy  recognizes  the  many  important  steps 
that  public  and  private  entities  across  the  country 
have  taken  in  response  to  the  W orld  T rade  C  enter  and 
Pentagon  attacks  on  September  11,  2001,  to  improve 
the  security  of  their  critical  facilities,  systems,  and 
functions.  Building  on  these  efforts,  this  Strategy 
provides  direction  to  the  federal  departments  and 
agencies  that  have  a  role  in  critical  infrastructure  and 
key  asset  protection.  It  also  suggests  steps  that  state 
and  local  governments,  private  sector  entities,  and 
concerned  citizens  across  A  merica  can  take  to 
enhance  our  collective  infrastructure  and  asset  security. 
Accordingly,  this  Strategy  belongs  and  applies  to  the 
N  ation  as  a  whole,  not  just  to  the  federal  government 
or  its  constituent  departments  and  agencies. 

This  Strategy  complements  the  N  ational  Strategy  to 
Secure  Cyberspace,  which  focuses  on  the  identification, 
assessment,  and  protection  of  interconnected  informa¬ 
tion  systems  and  networks.  T  he  Physical  and  Cyber 
Strategies  share  common  underlying  policy  objectives 
and  principles.  T ogether,  they  form  the  road  ahead  for 
one  of  our  core  homeland  security  mission  areas. 

A  NEW  MISSION 
T  he  September  11  attacks  on  the  W orld  T rade  C  enter 
and  the  Pentagon  demonstrated  our  national -level 
physical  vulnerability  to  the  threat  posed  by  a  formi¬ 
dable  enemy— focused,  mass  destruction  terrorism. 

T  he  events  of  that  day  also  validated  how  determined, 
patient,  and  sophisticated— in  both  planning  and 
execution—  our  terrorist  enemies  have  become. 

I  ronically,  the  basic  nature  of  our  free  society  greatly 
enables  terrorist  operations  and  tactics,  while,  at  the 
same  time,  it  hinders  our  ability  to  predict,  prevent, 
or  mitigate  the  effects  of  terrorist  acts.  G  iven  these 


realities,  it  is  imperative  to  develop  a  comprehensive 
national  approach  to  physical  protection. 

Protecting  America’s  critical  infrastructures  and  key 
assets  represents  an  enormous  challenge.  0  ur  N  ation's 
critical  infrastructures  and  key  assets  are  a  highly 
complex,  heterogeneous,  and  interdependent  mix  of 
facilities,  systems,  and  functions  that  are  vulnerable  to  a 
wide  variety  of  threats.  T  heir  sheer  numbers,  pervasive¬ 
ness,  and  interconnected  nature  create  an  almost 
infinite  array  of  high-payoff  targets  for  terrorist 
exploitation.  G  iven  the  immense  size  and  scope  of  the 
potential  target  set,  we  cannot  assume  that  we  will  be 
able  to  protect  completely  all  things  at  all  times  against 
all  conceivable  threats.  As  we  develop  protective 
measures  for  one  particular  type  of  target,  our  terrorist 
enemies  will  likely  focus  on  another.  To  be  effective, 
our  national  protection  strategy  must  be  based  on  a 
thorough  understanding  of  these  complexities  as  we 
build  and  implement  a  focused  plan  for  action. 

DEFINING  THE  END  STATE: 
STRATEGIC  OBJECTIVES 

T o  frame  the  initial  focus  of  our  national  protection 
effort,  we  must  acknowledge  that  the  assets,  systems, 
and  functions  that  comprise  our  infrastructure  sectors 
are  not  uniformly  "critical"  in  nature,  particularly  in  a 
national  or  major  regional  context. 

T  he  first  objective  of  this  Strategy  is  to  identify  and 
assure  the  protection  of  those  assets,  systems,  and 
functions  that  we  deem  most  "critical"  in  terms  of 
national -level  public  health  and  safety,  governance, 
economic  and  national  security,  and  public  confidence. 
We  must  develop  a  comprehensive,  prioritized 
assessment  of  facilities,  systems,  and  functions  of 
national -level  criticality  and  monitor  their  prepared¬ 
ness  across  infrastructure  sectors.  T  he  federal 
government  will  work  closely  with  state  and  local 
governments  and  the  private  sector  to  establish  a 
uniform  methodology  for  determining  national -level 
criticality.  T  his  methodology  will  enable  a  focus  on 
high-priority  activities  and  the  development  of 
consistent  approaches  to  counter  the  terrorist  threat. 

T  he  second  major  objective  is  to  assure  the  protection 
of  infrastructures  and  assets  that  face  a  specific, 
imminent  threat.  Federal,  state,  and  local  governments 
and  private- sector  partners  must  collaborate  closely  to 
develop  thorough  assessment  and  alert  processes  and 
systems  to  ensure  that  threatened  assets  receive  timely 
advance  warnings.  T  hese  entities  must  further 
cooperate  to  provide  focused  protection  against  the 
anticipated  threat. 


2  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


Finally,  as  we  act  to  secure  our  most  critical 
infrastructures  and  assets,  we  must  remain  cognizant 
that  criticality  varies  as  a  function  of  time,  risk,  and 
market  changes.  Acting  to  better  secure  our  highest 
priority  facilities,  systems,  and  functions,  we  should 
expect  our  terrorist  enemies  to  shift  their  destructive 
focus  to  targets  they  consider  less  protected  and  more 
likely  to  yield  desired  shock  effects.  FI  ence,  the  third 
objective  of  this  Strategy  is  to  pursue  collaborative 
measures  and  initiatives  to  assure  the  protection  of 
other  potential  targets  that  may  become  attractive  over 
time.  The  focus  will  be  to  foster  an  environment  in 
which  key  public-  and  private- sector  stakeholders  can 
better  protect  the  infrastructures  and  assets  they 
control  according  to  their  specific  responsibilities, 
competencies,  and  capabilities. 

T  he  last  three  chapters  of  this  Strategy  detail  the 
cross- sector  and  sector- specific  priority  solution 
paths  we  will  pursue  to  achieve  the  fullest  measure 
of  national  protection  possible  across  all  categories 
of  critical  infrastructures  and  key  assets. 

HOMELAND  SECURITY 
AND  INFRASTRUCTURE 

protection:  a  shared 

RESPONSIBILITY 

Protecting  America’s  critical  infrastructures  and  key 
assets  calls  for  a  transition  to  an  important  new 
national  cooperative  paradigm.  T  he  basic  tenets  of 
homeland  security  are  fundamentally  different  from  the 
historically  defined  tenets  of  national  security. 

FI  istorically,  securing  the  U  nited  States  entailed  the 
projection  of  force  outside  of  our  borders.  W e 
protected  ourselves  by  "keeping  our  neighborhood  safe” 
in  the  global,  geopolitical  sense.  The  capability  and 
responsibility  to  carry  out  this  mission  rested  largely 
with  the  federal  government. 

The  emergence  of  international  terrorism  within  our 
borders  has  moved  the  front  line  of  domestic  security 
to  M  ain  Street,  U.S.A .  Faced  with  the  realities  of  the 
September  11  attacks,  the  mission  of  protecting  our 
homeland  now  entails  "keeping  our  neighborhood  safe” 
in  the  most  literal  sense.  Safeguarding  our  l\l  ation 
against  the  terrorist  threat  depends  on  our  ability  to 
marshal  and  project  appropriate  resources  inward. 
Respect  for  the  open,  pluralistic  nature  of  our  society; 
the  individual  rights  and  liberties  of  our  citizenry;  and 
our  federalist  system  of  government  define  the 
framework  within  which  security  can  be  implemented. 

Acting  alone,  the  federal  government  lacks  the 
comprehensive  set  of  tools  and  competencies  required 


V  omeland  security  is  a  concerted 
national  effort  to  prevent  terrorist 
attacks  within  the  United  States*  reduce 
A  m erica's  vulnerability  to  terrorism, 
and  minimizethedamageand  recover 
from  attacks  that  do  occur. " 

-TheN  ational  Strategy  for  H  omeland  Security 

to  deliver  the  most  effective  protection  and  response 
for  most  homeland  security  threats.  T  herefore,  to 
combat  the  threat  terrorism  poses  for  our  critical 
infrastructures  and  key  assets,  we  must  draw  upon  the 
resources  and  capabilities  of  those  who  stand  on  the 
new  front  lines— our  local  communities  and  private 
sector  entities  that  comprise  our  national  critical 
infrastructure  sectors. 

Forging  this  unprecedented  level  of  cooperation  will 
require  dramatic  changes  in  the  institutional  mindsets 
honed  and  shaped  by  Cold  War-era  regimes.  Success 
in  this  effort  must  be  built  and  sustained  over  time. 
ThisStrategy  provides  a  starting  point  for  defining  how 
this  national- level  cooperation  can  best  be  achieved. 

I  n  the  context  of  a  new  national  cooperative  paradigm, 
this  Strategy  further  serves  as  an  important  vehicle  for 
educating  the  public  and  achieving  realistic  expecta¬ 
tions  on  the  emergent  terrorist  threat  and  the  roles 
government  and  industry  must  play  in  defending 
against  it.  Public  understanding  and  acceptance  of  this 
Strategy  is  essential.  T  he  A  merican  public's  resilience 
and  support  will  be  sustainable  in  the  aftermath  of 
future  terrorist  attacks  only  if  expectations  are  clearly 
defined,  attainable,  and  fulfilled. 

STRATEGY  OVERVIEW 

T  his  Strategy  is  comprehensive  in  scope  and  focused 
in  detail.  The  following  chapters  lay  out  a  roadmap  to 
identify  specific  priority  actions  to  be  taken  to  assure 
more  comprehensive  protection  of  our  critical 
infrastructures  and  key  assets. 

The  Case  for  Action 

T  his  chapter  discusses  the  role  critical  infrastruc¬ 
tures  and  key  assets  play  as  a  foundation  of  our 
N  ation's  economic  security,  governance,  national 
defense,  public  health  and  safety,  and  public 
confidence.  It  describes  in  greater  detail  the  charac¬ 
teristics  of  terrorism  and  the  challenges  we  must 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  3 


address  to  protect  the  N  ation’s  critical 
infrastructures  and  key  assets  against  this  threat. 

N  ational  Policy  and  G  uiding  Principles 

This  chapter  describes  the  overarching  national 
policy  and  guiding  principles  that  underpin  this 
Strategy  and  our  collective  approach  to  action. 

0  rganizing  and  Partnering  for  C  ritical  I  nfrastructure 

and  K  ey  Asset  P  rotection 

This  chapter  provides  an  organizational  structure 
for  our  national- level  critical  infrastructure  and  key 
asset  protection  effort.  It  also  clarifies  key  public- 
and  private- sector  roles  and  responsibilities  and 
provides  a  collaborative  framework  for  cross- sector 
and  cross-jurisdictional  infrastructure  and 
asset  protection. 

C  ross-  Sector  Security  P  riorities 

T  his  chapter  addresses  important  cross- sector 
issues,  impediments  to  action,  and  the  steps 
necessary  to  address  them.  It  describes  actions  to 
foster  cooperation,  lower  costs,  and  provide  leverage 
across  key  issue  areas  for  maximum  effect.  I  n 
concert,  these  initiatives  form  the  framework 
through  which  we  will  align  the  resources  of  the 
federal  budget  to  the  critical  infrastructure  and 
key  asset  protection  mission. 


Securing  C  ri  deal  I  nfrastructures 

This  chapter  outlines  protection  priorities  for 
the  critical  infrastructure  sectors  identified  in 
the  N  ational  Strategy  for  H  omeland  Security.  T  he 
overviews  provided  are  designed  to  highlight  pressing 
issues  in  need  of  concerted  attention  at  the  individual 
sector  level.  E  ach  federal  lead  department  and  agency 
will  develop  plans  and  programs  to  implementor 
facilitate  these  priority  sector  initiatives. 

Protecting  Key  Assets 

T  his  chapter  describes  protection  considerations  for 
unique  facilities,  such  as  dams,  nuclear  power  plants, 
and  national  monuments  and  icons  whose  attack,  in  a 
worst- case  scenario,  could  present  significant  health 
and  safety  and/or  public  confidence  consequences. 

C  ondusion 

T  his  chapter  summarizes  the  next  steps  required 
to  assure  comprehensive  protection  of  our  critical 
infrastructures  and  key  assets. 


1  T  he  primary  focus  of  this  Strategy  is  the  physical  protection 
of  critical  infrastructures  and  key  assets.  T  he  protective 
strategy  for  information  technology  and  network  assets  for 
specific  sectors  is  discussed  in  detail  in  the  National  Strategy 
to  Secure  Cyberspace.  A  ccordi  ngly,  the  protecti  on  of  the 
I  nformation  T echnology  component  of  the  I  nformation  and 
Telecommunications  sector  is  not  discussed  in  this  document. 


4  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


C  T  I  O  N 


THE  CASE  FOR  A 


D  eveloping  an  effective  strategy  for  critical 
infrastructure  and  key  asset  protection  requires  a  clear 
understanding  of  the  threats  we  face  and  the  potential 
consequences  they  entail.  T  he  September  11  attacks 
were  a  wake-up  call.  Before  these  devastating  events, 
we,  as  Americans,  considered  ourselves  relatively 
immune  to  a  massive  physical  attack  on  our  homeland. 
0  ur  victory  in  the  Cold  War  left  us  with  few  signifi¬ 
cant  conventional  military  threats,  and  the  world  of 
terrorism  seemed  more  the  concern  of  troubled  regions 
like  the  M  iddle  E  ast  than  M  iddle  America.  Asa 
N  ation,  we  were  generally  unfamiliar  with  the  motiva¬ 
tions  of  terrorists  and  the  deep  hatred  behind  their 
agendas.  Furthermore,  we  underestimated  the  depth 
and  scope  of  their  capabilities  and  did  not  fully  appre¬ 
ciate  the  extent  to  which  they  would  go  to  carry  out 
their  destructive  acts.  T  he  September  11  attacks 
changed  these  misconceptions. 


A  l-Q  aeda  terrorists  exploited  key  elements  of  our  own 
transportation  infrastructure  as  weapons.  T  heir  targets 
were  key  assets  symbolic  of  our  national  prestige  and 
military  and  economic  power.  T  he  effects  of  the  attacks 
cascaded  throughout  our  society,  economy,  and  govern¬ 
ment.  As  a  N  ation,  we  became  suddenly  and  painfully 
aware  of  the  extent  of  our  domestic  vulnerability- 
more  so  than  at  anytime  since  the  Second  World  War. 

T o  protect  our  critical  infrastructures  and  key  assets 
from  further  terrorist  exploitation,  we  must  understand 
the  intent  and  objectives  of  terrorism  as  well  as  the 
tactics  and  techniques  its  agents  could  employ  against 
various  types  of  targets.  W  e  must  complement  this 
understanding  with  a  comprehensive  assessment  of  the 
assets  to  be  protected,  their  vulnerabilities,  and  the 
challenges  associated  with  eliminating  or  mitigating 
those  vulnerabilities— a  task  that  will  require  the 
concerted  efforts  of  our  entire  N  ation. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  5 


THE  SIGNIFICANCE  OF 
CRITICAL  INFRASTRUCTURES 
AND  KEY  ASSETS 

T  he  I  mportance  of  C  ritical  I  infrastructures 

A  merica’s  critical  infrastructure  sectors  provide  the 
goods  and  services  that  contribute  to  a  strong  national 
defense  and  thriving  economy.  M  oreover,  their 
continued  reliability,  robustness,  and  resiliency  create 
a  sense  of  confidence  and  form  an  important  part  of 
our  national  identity  and  strategic  purpose.  T  hey  also 
frame  our  way  of  life  and  enable  A  mericans  to  enjoy 
one  of  the  highest  overall  standards  of  living  of  any 
country  in  the  world. 

W  hen  we  flip  a  switch,  we  expect  light.  W  hen  we  pick 
up  a  phone,  we  expect  a  dial  tone.  W  hen  we  turn  a  tap, 
we  expect  drinkable  water.  E  lectricity,  clean  water,  and 
telecommunications  are  only  a  few  of  the  critical  infra¬ 
structure  services  that  we  tend  to  take  for  granted.  T  hey 
have  become  so  basic  in  our  daily  lives  that  we  notice 
them  only  when,  for  some  reason,  service  is  disrupted. 

W  hen  disruption  does  occur,  we  expect  reasonable 
explanations  and  speedy  restoration  of  service. 

T  he  N ational  Strategy  for  H  omeland  Security  categorizes 
our  critical  infrastructures  into  the  following  sectors: 


CRITICAL  INFRASTRUCTURE 
SECTORS 

Agriculture 

Food 

Water 

Public  H  ealth 
E  mergency  Services 
G  overnment 
D  efense  I  industrial  Base 
Information  and  Telecommunications 
E  nergy 

T  ransportation 
Banking  and  Finance 

C  hemical  I  ndustry  and  H  azardous  M  aterials 
Postal  and  Shipping 


C  ritical  infrastructures  are  'Systems  and 
assets,  whether  physical  or  virtual,  so 
vital  to  the  U  nited  States  that  the 
incapacity  or  destruction  of  such  systems 
and  assets  would  havea  debilitating 
impact  on  security,  national  economic 
security,  national  public  health  or  safety, 
or  any  combination  of  those  matters. " 

-  USA  Patriot  Act 

Together  these  industries  provide: 

Production  and  D  eliveryofE  ssential  G oodsand  Services 

C  ritical  infrastructure  sectors  such  as  agriculture, 
food,  and  water,  along  with  public  health  and 
emergency  services,  provide  the  essential  goods  and 
services  that  A  mericans  depend  on  to  survive. 

E  nergy,  transportation,  banking  and  financial 
services,  chemical  manufacturing,  postal  services, 
and  shipping  sustain  the  N  ation’s  economy  and 
make  possible  and  available  a  continuous  array  of 
goods  and  services. 

I  nterconnectednessand  0  perability 

Information  and  telecommunications  infrastructures 
connect  and  increasingly  control  the  operations  of 
other  critical  infrastructures. 

P  ublic  Safety  and  Security 

0  ur  government  institutions  guarantee  our  national 
security,  freedom,  and  governance,  as  well  as  services 
that  make  up  the  N  ation’s  public  safety  net. 

The  facilities,  systems,  and  functions  that  comprise  our 
critical  infrastructures  are  highly  sophisticated  and 
complex.  T  hey  consist  of  human  capital  and  physical 
and  cyber  systems  that  work  together  in  processes  that 
are  highly  interdependent.  T  hey  each  encompass  a 
series  of  key  nodes  that  are,  in  turn,  essential  to  the 
operation  of  the  critical  infrastructures  in  which  they 
function.  T o  complicate  matters  further,  our  most 
critical  infrastructures  typically  interconnect  and, 
therefore,  depend  on  the  continued  availability  and 
operation  of  other  dynamic  systems  and  functions. 

For  example,  e- commerce  depends  on  electricity  as 
well  as  information  and  communications.  Assuring 
electric  service  requires  operational  transportation  and 
distribution  systems  to  guarantee  the  delivery  of  fuel 
necessary  to  generate  power.  Such  interdependencies 


6  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


have  developed  over  time  and  are  the  product  of 
innovative  operational  processes  that  have  fueled 
unprecedented  efficiency  and  productivity.  G  iven  the 
dynamic  nature  of  these  interdependent  infrastructures 
and  the  extent  to  which  our  daily  lives  rely  on  them, 
a  successful  terrorist  attack  to  disrupt  or  destroy  them 
could  have  tremendous  impact  beyond  the  immediate 
target  and  continue  to  reverberate  long  after  the 
immediate  damage  is  done. 

T  he  I  mportance  of  Key  A  ssets 

Key  assets  represent  individual  targets  whose  destruc¬ 
tion  could  cause  large-scale  injury,  death,  or  destruction 
of  property,  and/or  profoundly  damage  our  national 
prestige,  and  confidence.  Such  assets  and  activities 
alone  may  not  be  vital  to  the  continuity  of  critical 
services  on  a  national  scale,  but  an  attack  on  any  one  of 
them  could  produce,  in  the  worst  case,  significant  loss 
of  life  and/or  public  health  and  safety  consequences. 
This  category  includes  such  facilities  as  nuclear  power 
plants,  dams,  and  hazardous  materials  storage  facilities. 

Other  key  assets  are  symbolically  equated  with 
traditional  A  merican  values  and  institutions  or  U  .S. 
political  and  economic  power.  0  ur  national  symbols, 
icons,  monuments,  and  historical  attractions  preserve 
history,  honor  achievements,  and  represent  the  natural 
grandeur  of  our  country.  T  hey  also  celebrate  our 
A  merican  ideals  and  way  of  life—  a  key  target  of 
terrorist  attacks.  Successful  terrorist  strikes  against  such 
assets  could  profoundly  impact  national  public  confi¬ 
dence.  M  onuments  and  icons,  furthermore,  tend  to  be 
gathering  places  for  large  numbers  of  people,  particu¬ 
larly  during  high-profile  celebratory  events— a  factor 
that  adds  to  their  attractiveness  as  targets. 

0  wnership  of  key  assets  varies.  T  he  private  sector  owns 
and  operates  dams  and  nuclear  power  plants  as  well  as 
most  of  this  N  ation’s  large  buildings  holding  important 
commercial  and/or  symbolic  value  and/or  housing  large 
numbers  of  people.  T  he  protection  of  national  monu¬ 
ments  and  icons  often  entails  overlapping  state,  local, 
and  federal  jurisdictions.  Some  are  managed  and  oper¬ 
ated  by  private  foundations.  These  realities  complicate 
our  protective  efforts. 

UNDERSTANDING 
THE  THREAT 

C  haracteristics  of  T  errorism 

T  he  September  11  attacks  offered  undeniable  proof 
that  our  critical  infrastructures  and  key  assets  represent 
high-value  targets  for  terrorism.  T  he  attacks  under¬ 
scored  the  determination  and  patience  of  our  terrorist 
enemies.  T  he  highly  coordinated  nature  of  the  strikes 


demonstrated  a  previously  unanticipated  level  of 
sophistication  in  terms  of  planning  and  execution. 

T  hrough  these  attacks,  A  l-Q  aeda  terrorists  also  showed 
a  dogged  resolve  in  pursuit  of  their  objectives.  W  hen 
their  first  attempt  to  topple  the  World  Trade  Center 
towers  failed  in  1993,  they  persisted  by  planning  and 
executing  a  second  attack  eight  years  later  that  proved 
to  be  more  successful  than  even  they  expected. 

0  ur  terrorist  enemies  have  proven  themselves  to  be 
opportunistic  and  flexible.  As  illustrated  by  the  two 
separate  W orld  T rade  C  enter  attacks,  they  learn  from 
experience  and  modify  their  tactics  accordingly.  T  hey 
also  adapt  their  methods  in  order  to  exploit  newly 
observed  or  perceived  vulnerabilities.  As  security 
increases  around  more  predictable  targets,  they  will 
likely  seek  more  accessible  and  less  protected  facilities 
and  events.  E  nhancing  countermeasures  against  any 
one  terrorist  tactic,  therefore,  makes  it  more  likely  that 
terrorists  will  favor  another. 

T errorists  are  inventive  and  resourceful  in  terms  of 
target  selection,  as  well  as  in  the  selection  and  use  of 
specific  instruments  of  violence  and  intimidation.  T  hey 
exploit  vulnerabilities  wherever  they  exist,  with  any 
means  at  their  disposal,  at  times  and  locations  of  their 
choosing.  T errorists  are  attempting  to  acquire  a  broad 
range  of  weapons,  from  high-yield  conventional 
explosives  and  firearms  to  weapons  of  mass  destruc¬ 
tion.  Oftentimes  the  nature  of  the  target  will  dictate 
the  weapon  of  choice.  Other  times  the  availability  of  a 
particular  type  of  weapon,  such  as  a  nuclear  or 
biological  device,  will  determine  target  selection. 

The  matching  of  means  to  ends  is  limited  only  by  the 
creativity  and  resources  of  the  terrorists;  the  only 
constant  is  their  desire  to  inflict  maximum  destruction, 
injury,  and  shock  in  pursuit  of  their  strategic  objectives. 

T errorism  is  with  us  for  the  foreseeable  future. 
Following  the  September  11  attacks,  President  Bush 
stated  that  the  war  on  terrorism  would  be  a  long-term 
effort.  W  hile  the  tools  and  tactics  of  terrorists  may 
change,  their  fundamental  determination  remains  the 
same.  T  hose  with  enmity  toward  the  U  ,S.  and  its 
interests  consider  terrorism  an  effective  weapon  to  use 
against  us,  and  they  will  continue  to  employ  such 
tactics  until  we  can  prove  that  it  is  not. 

T  he  N  ature  of  Possible  Attacks 

The  terrorist  endgame  includes  a  complex  mix  of 
political,  economic,  and  psychological  objectives.  To 
achieve  their  objectives,  terrorists  may  choose  to  target 
critical  infrastructures  and  key  assets  as  low-risk  means 
to  generate  mass  casualties,  shock,  and  panic. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  7 


T errorists  target  critical  infrastructure  and  key  assets  to 
achieve  effects  that  fall  into  three  general  categories: 

•  D  irect  infrastructure  effects  C  ascading  disruption  or 
arrest  of  the  functions  of  critical  infrastructures  or 
key  assets  through  direct  attacks  on  a  critical  node, 
system,  or  function. 

The  immediate  damage  to  facilities  and  disruption 
of  services  that  resulted  from  the  attack  on  the 
W orld  T rade  C  enter  towers,  which  housed  critical 
assets  of  the  financial  services  sector,  are  examples  of 
direct  infrastructure  effects. 

•  Indirect  infrastructure  effects:  C  ascading  disruption 
and  financial  consequences  for  government,  society, 
and  economy  through  public-  and  private- sector 
reactions  to  an  attack. 

Public  disengagement  from  air  travel  and  other 
facets  of  the  economy  as  a  result  of  the  September 
11  attacks  exemplifies  this  effect.  M  iti gating  the 
potential  consequences  from  these  types  of  attacks 
will  require  careful  assessment  of  policy  and  regula¬ 
tory  responses,  understanding  the  psychology  of 
their  impacts,  and  appropriately  weighing  the  costs 
and  benefits  of  specific  actions  in  response  to 
small-scale  attacks. 

•  Exploitation  of  infrastructure  Exploitation  of 
elements  of  a  particular  infrastructure  to  disrupt  or 
destroy  another  target. 

0  n  September  11,  terrorists  exploited  elements  of 
the  aviation  infrastructure  to  attack  the  World  T  rade 
Center  and  the  Pentagon,  which  represented  seats 
of  U.S.  economic  and  military  power.  D  etermining 
the  potential  cascading  and  cross- sector  conse¬ 
quences  of  this  type  of  attack  is  extremely  difficult. 

CHALLENGES  TO  PROTECTING 
CRITICAL  INFRASTRUCTURES 
AND  KEY  ASSETS 

The  New  Front  Lines 

0  ur  technologically  sophisticated  society  and 
institutions  present  a  wide  array  of  potential  targets 
for  terrorist  exploitation.  0  ur  critical  infrastructure 
industries  change  rapidly  to  reflect  the  demands  of  the 
markets  they  serve.  M  uch  of  the  expertise  required  for 
planning  and  taking  action  to  protect  critical  infrastruc¬ 
tures  and  key  assets  lies  outside  the  federal  government, 
including  precise  knowledge  of  what  needs  to  be 
protected.  I  n  effect,  the  front  lines  of  defense  in  this 
new  type  of  battle  have  moved  into  our  communities 
and  the  individual  institutions  that  make  up  our 
critical  infrastructure  sectors. 


Private  industry  owns  and  operates  approximately 
85  percent  of  our  critical  infrastructures  and  key  assets. 
Facility  operators  have  always  been  responsible  for 
protecting  their  physical  assets  against  unauthorized 
intruders.  T  hese  measures,  however  conventionally 
effective,  generally  have  not  been  designed  to  cope  with 
significant  military  or  terrorist  threats,  or  the  cascading 
economic  and  psychological  impact  they  may  entail. 

T  he  unique  characteristics  of  critical  infrastructures  and 
key  assets,  their  continuing— often  rapid— evolution, 
and  the  significant  impediments  complicating  their 
protection  will  require  an  unprecedented  level  of  key 
public-  and  private- sector  cooperation  and  coordination. 
0  ur  country  has  more  than  87,000  jurisdictions  of  local 
governance  alone.  T  he  challenge  ahead  is  to  develop  a 
coordinated  and  complementary  system  that  reinforces 
protection  efforts  rather  than  duplicates  them,  and  that 
meets  mutually  identified  essential  requirements.  I  n 
addition,  many  of  our  critical  infrastructures  also  span 
national  borders  and,  therefore,  must  be  protected 
within  the  context  of  international  cooperation. 

A  NEW  paradigm: 
COOPERATION 
AND  PARTNERSHIP 

0  ur  open  society,  highly  creative  and  responsive 
economic  markets,  and  system  of  values  that  engenders 
individual  recognition  and  freedom  have  created  wealth 
for  our  nation,  built  a  strong  national  security  system, 
and  instilled  a  sense  of  national  confidence  in  the 
future.  D  estruction  of  our  traditions,  values,  and  way  of 
life  represents  a  key  objective  of  our  terrorist  enemies. 

I  ronically,  the  tenets  of  A  merican  society  that  make  us 
free  also  create  an  environment  that  facilitates 
terrorist  operations. 

A  s  we  strive  to  understand  the  nature  of  terrorism  and 
identify  appropriate  means  to  defend  against  it,  we  will 
require  new  collaborative  structures  and  mechanisms 
for  working  together.  D  uring  the  C  old  W ar  era,  many 
government  and  private  organizations  isolated  parts 
of  their  physical  and  information  infrastructures  into 
"stovepipes”  to  assure  their  protection.  T  his  approach 
is  no  longer  adequate  to  protect  our  homeland  from 
determined  terrorists.  Stimulating  voluntary,  rapidly 
adaptive  protection  activities  requires  a  culture  of  trust 
and  ongoing  collaboration  among  relevant  public-  and 
private- sector  stakeholders,  rather  than  more  tradi¬ 
tional  systems  of  command  and  control. 

Security  investments  made  by  all  levels  of  government 
and  private  industry  have  increased  since  the 
September  11  attacks.  As  terrorism  continues  to 
evolve,  so  must  the  way  in  which  we  protect  our 


8  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


country  and  ourselves.  T  he  costs  of  protection- 
including  expenditures  to  develop  new  technologies, 
tools,  and  procedures— will  weigh  heavily  on  all  levels 
of  government  and  private  industry.  C  onsequently,  an 
effective  protection  strategy  must  incorporate  well- 
planned  and  highly  coordinated  approaches  that  have 
been  developed  by  the  best  minds  in  our  country 
through  innovation  and  sharing  of  information,  best 
practices,  and  shared  resources. 

N  ational  Resilience:  Sustaining  Protection 
for  the  Long  Term 

Combating  terrorism  will  be  a  long-term  effort.  Its 
dynamic  nature  means  that  we  must  enhance  the 
protection  of  our  critical  infrastructures  and  key  assets 
in  an  environment  of  persistent  and  evolving  threats. 

0  ur  N  ation’s  critical  infrastructures  are  generally 
robust  and  resilient.  T  hese  attributes  result  from 
decades  of  experience  gained  from  responding  to 
natural  disasters,  such  as  hurricanes  and  floods,  and 
the  deliberate  acts  of  malicious  individuals.  T  he 
critical  infrastructure  sectors  have  learned  from  each 
disruption  and  applied  those  lessons  to  improve  their 
protection,  response,  and  recovery  operations.  For 
example,  during  the  immediate  aftermath  of  the 
September  11  attacks,  the  electric  system  in  N  ew  York 
C  ity  remained  operational  for  the  island  of  M  anhattan 
outside  of  the  W orld  T rade  C  enter  complex—  G  round 
Zero.  Furthermore,  needed  electric  service  at  G  round 
Zero  was  quickly  and  efficiently  restored  to  support 
rescue  and  recovery  operations.  T  his  success  is  a  good 
example  of  American  ingenuity,  as  well  as  a  tenacious 
application  of  lessons  learned  from  the  1993  World 
T rade  C  enter  bombing  and  other  terrorist  events. 

Resilience  is  characteristic  of  most  U.S.  communities, 
and  it  is  reflected  in  the  ways  they  cope  with  natural 
disasters.  0  ver  time,  residents  of  communities  in  areas 
that  are  persistently  subjected  to  natural  disasters 
become  accustomed  to  what  to  expect  when  one 
occurs.  I  nstitutions  and  residents  in  such  areas  grow  to 
understand  the  nature  of  catastrophic  events,  as  well  as 
their  roles  and  responsibilities  in  managing  their  after¬ 
effects.  T  hey  are  also  familiar  with  and  rely  on  trusted 
community  systems  and  resources  that  are  in  place 
to  support  protection,  response,  and  recovery  efforts. 
Asa  result,  they  have  confidence  in  their  communities’ 
abilities  to  contend  with  the  aftermath  of  disasters 
and  learn  from  each  event. 

Institutions  and  residents  nationwide  must  likewise 
come  to  understand  the  nature  of  terrorism,  its  conse¬ 
quences,  and  the  role  they  play  in  combating  it.  Ideally, 
they  will  become  familiar  with  and  have  confidence  in 


THE  PROTECTION 

CHALLENGE 

Agriculture  and  Food 

1,912,000  farms;  87,000 
food- processing  plants 

Water 

1,800  federal  reservoirs; 
1,600  municipal  waste 
water  facilities 

Public  H  ealth 

5,800  registered 
hospitals 

E  mergency  Services 

87,000  U.S.  localities 

Defense  Industrial  Base 

250,000  firms  in  215 
distinct  industries 

T  elecomm  unications 

2  billion  miles  of  cable 

E  nergy 

Electricity 

2,800  power  plants 

Oil  and  Natural  Gas 

300,000  producing  sites 

T  ransportation 

Aviation 

5,000  public  airports 

Passenger  R  ail 
and  Railroads 

120,000  miles  of  major 
railroads 

H  ighways,  T rucking, 
and  Busing 

590,000  highway 
bridges 

Pipelines 

2  million  miles  of 
pipelines 

M  arid  me 

300  inland/ costal  ports 

M  ass  T  ran  sit 

500  major  urban  public 
transit  operators 

Banking  and  Finance 

26,600  FDIC  insured 
institutions 

C  hemical  1  ndustry  and 

H  azardous  M  aterials 

66,000  chemical  plants 

Postal  and  Shipping 

137  million  delivery 
sites 

KeyAssets 

National  M  onuments 
and  Icons 

5,800  historic  buildings 

Nudear  Power  Plants 

104  commercial  nuclear 
power  plants 

Dams 

80,000  dams 

Government  F  adlities 

3,000  government 
owned/operated  facilities 

Commerdal  Assets 

460  skyscrapers 

*T  hese  are  approximate  figures. 

THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  9 


the  protection,  response,  and  recovery  mechanisms  that 
exist  within  their  communities.  Together  with  local 
officials,  private  organizations  and  residents  must  work 
to  improve  these  systems  and  resources  to  meet  the 
challenge  of  safeguarding  our  country  from  terrorists. 

0  ur  challenge  is  to  identify,  build  upon,  and  apply  the 
lessons  learned  from  the  September  11  attacks  to 


anticipate  and  protect  against  future  terrorist  attacks  on 
our  critical  infrastructures  and  key  assets.  0  ur  ability  to 
do  so  will  determine  how  successfully  we  adapt  to  the 
current  dynamic  threat  environment  and  whether  we 
can  emerge  as  a  stronger,  more  vibrant  nation  with  our 
values  and  way  of  life  intact. 


10  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


NATIONAL  POLICY  AND 
GUIDING  PRINCIPLES 


STATEMENT  OF 
NATIONAL  POLICY 

This  document  reaffirms  our  N  ation's  longstanding 
policy  regarding  critical  infrastructure  and  key  asset 
protection.  It  also  delineates  a  set  of  guiding  principles 
that  underpins  our  strategy  for  action  to  protect  our 
N  ation’s  critical  infrastructures  and  key  assets  from 
terrorist  attack. 

As  a  N  ation,  we  are  committed  to  protecting  our 
critical  infrastructures  and  key  assets  from  acts  of 
terrorism  that  would: 

•  I  mpair  the  federal  government's  ability  to  perform 
essential  national  security  missions  and  ensure  the 
general  public’s  health  and  safety; 

•  U  ndermine  state  and  local  government  capacities  to 
maintain  order  and  to  deliver  minimum  essential 
public  services; 

•  D  amage  the  private  sector’s  capability  to  ensure  the 
orderly  functioning  of  the  economy  and  the  delivery 
of  essential  services;  and 

•  U  ndermine  the  public’s  morale  and  confidence  in 
our  national  economic  and  political  institutions. 

As  a  N  ation,  we  must  utilize  every  tool  at  our  disposal 
and  work  collaboratively  to  develop  and  implement  the 
protective  measures  that  this  policy  entails.  T  he 
strategic  objectives  discussed  in  the  Introduction  will 
focus  and  drive  this  effort. 

GUIDING  PRINCIPLES 

0  ur  domestic  protection  efforts  are  grounded  in  core 
strengths  and  values  that  we  have  traditionally  relied 
upon  during  major  periods  of  crisis  in  our  N  ation's 
history.  U  sing  these  core  strengths  and  values  as  a 
guide,  eight  principles  underpin  this  Strategy  and  its 
associated  enabling  initiatives: 

1.  Assure  public  safety,  public  confidence, 
and  services 

Anticipating  that  widespread  or  large-scale 
disruptions  will  undermine  public  confidence  in  our 
political  and  economic  institutions,  terrorists  will 
continue  to  use  horrific  violence  against  people  and 
property  to  impact  the  efficient  functioning  of  our 


society  and  economy.  By  making  strategic  improve¬ 
ments  in  security  and  reducing  the  vulnerability  of 
our  N  ation's  critical  infrastructures  and  key  assets  to 
such  physical  attack— particularly  those  involving 
the  most  catastrophic  potential  consequences— this 
strategy  seeks  to  reassure  the  public  and  reinforce  its 
confidence  in  our  institutions  and  systems. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  11 


By  making  our  infrastructures  and  key  assets  more 
robust  through  such  measures  as  deliberate  redun¬ 
dancies,  hardening,  and  dispersal,  we  increase  their 
capacity  to  withstand  attack  without  sustaining 
significant  damage.  T  hrough  effective  protection 
and  response  planning,  we  make  them  more 
resilient  to  allow  for  the  quick  restoration  of  critical 
services  to  minimize  the  detrimental  effects  to  our 
economy  and  public  welfare.  I  mplementing  and 
exercising  well- developed  plans  assures  their 
effectiveness  in  times  of  crisis  and  is  key  to  shaping 
public  expectations  and  instilling  confidence  in  our 
N  ation’s  ability  to  manage  the  aftermath  of 
terrorist  attacks. 

2.  E  stablish  responsibility  and  accountability 

T  his  Strategy  recognizes  the  crucial  role  of 
government,  industry,  and  the  public  at  large  in 
protecting  our  critical  infrastructures  and  key  assets 
from  terrorist  attack.  0  ur  valued  heritage  of 
federalism  and  limited  government  decentralizes 
our  governance  and  affords  private  citizens  and 
institutions  with  certain  rights  and  freedoms  to 
conduct  their  lives  and  businesses.  I  n  this  context, 
organizations  and  individuals  outside  of  the  federal 
government  must  take  the  lead  in  many  aspects  of 
critical  infrastructure  and  key  asset  protection. 

C  onsequently,  a  key  component  of  this  Strategy 
is  the  delineation  of  roles,  responsibilities,  and 
accountability  among  the  various  public-  and 
private- sector  entities  that  have  an  important  part 
to  play  in  domestic  protection. This  necessarily 
encompasses  the  mechanisms  required  to  coordinate 
and  integrated  protection  policies,  planning, 
resource  management,  performance  measurement, 
and  enabling  initiatives  across  federal,  state,  and 
local  governments  and  the  private  sector. 

3.  E  ncourageand  fadlitate  partnering  among  all  lev  els  of 

government  and  between  government  and  industry 

C  ritical  infrastructure  and  key  asset  protection 
concerns  span  all  levels  of  government  as  well  as 
the  private  sector.  Protection  over  the  long  term  is 
necessarily  a  shared  responsibility  that  involves 
mustering  resources  and  expertise  nationwide.  T  he 
National  Strategy  for  H  omeland  Security  recognizes 
the  need  to  mobilize  our  entire  society  in  a  collec¬ 
tive  effort  to  defend  our  homeland.  Accordingly,  it 
places  great  emphasis  on  "the  crucial  role  of  state 
and  local  governments,  private  institutions,  and  the 
American  people."T his  principle  is  central  to  our 
critical  infrastructure  and  key  asset  protection  effort. 


Every  disruption  or  attack  is  initially  a  local 
problem.  Because  of  the  immediate  effects 
experienced  by  local  communities,  state  and  local 
governments,  and  private- sector  infrastructure 
owners  and  operators  invariably  form  the  vanguard 
of  response  when  terrorists  strike.  C  onsequently, 
public  confidence  depends  heavily  on  how  well  the 
community  implements  protective  measures  and 
plans  in  advance  of  a  crisis.  Accordingly,  the  federal 
government  will  provide  overall  support, 
coordination,  and  focused  leadership  to  foster  an 
environment  in  which  all  stakeholders  can  better 
carry  out  their  individual  protection  responsibilities. 

4.  E  n courage  market  solutions  whenever  possible; 

compensate  for  market  failure  with  focused  government 

intervention 

Protecting  our  N  ation's  critical  infrastructures  and 
key  assets  requires  a  broad  spectrum  of  possible 
government  actions,  including:  improving 
understanding  and  awareness  of  the  current  threat 
environment;  providing  threat  indications  and 
warnings;  investing  in  research  and  development; 
transferring  pilot  technology;  exploring  various 
forms  of  financial  incentives;  and  taking  targeted 
regulatory  action,  where  appropriate. 

T  hrough  this  Strategy,  the  federal  government  strives 
to  encourage  proactive,  market- based  protective 
solutions.  M  any  of  the  critical  infrastructure  sectors 
are  currently  highly  regulated,  and  additional  regula¬ 
tory  directives  or  mandates  should  only  be  necessary 
in  instances  where  market  forces  are  insufficient  to 
prompt  the  investments  necessary  to  assure  critical 
infrastructure  and  key  asset  protection.  T  hey  may 
also  be  used  when  a  uniform  national  standard  or 
coordinated  response  is  required  to  address  a  particu¬ 
larly  challenging  threat,  especially  in  the  context  of 
cross- sector  interdependencies. 

In  many  cases,  incentives  can  reinforce  knowledge 
and  experience  within  the  private  sector  and  state 
and  local  governments,  including  the  development 
of  new  tools  and  innovative  processes  that  are 
appropriate  for  their  particular  systems,  operations, 
and  security  challenges.  I  ncentives  can  also  help  to 
offset  certain  negative  aspects  of  market  dynamics, 
such  as  the  natural  tendency  of  market  pressures  to 
eliminate  redundancies,  and,  hence,  create  single 
points  of  failure. 

5.  Fadlitate  meaningful  information  sharing 

I  nformation  sharing  underpins  any  true  partnership 
and  is  necessary  to  mitigate  the  threat  posed  by  a 
cunning,  adaptive,  and  determined  enemy.  To 


12  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


formulate  comprehensive  security  plans  and  make 
informed  security  investment  and  action  decisions, 
individuals  and  institutions  alike  require  timely, 
accurate,  and  relevant  information.  Accordingly,  we 
must  adopt  measures  to  identify  and  evaluate  poten¬ 
tial  impediments  or  disincentives  to  security- related 
information  sharing  and  formulate  appropriate 
measures  to  overcome  these  barriers.  W e  must  also 
develop  and  facilitate  reliable,  secure,  and  efficient 
communications  and  information  systems  to 
support  meaningful  information  sharing  among 
various  public-  and  private-sector  entities. 

6.  Foster  international  security  cooperation 

Following  the  events  of  September  11,  the  U  nited 
States  moved  quickly  to  engage  friends  and  allies 
around  the  world  in  the  war  on  terrorism.  We  also 
took  prompt  action  with  Canada  and  M  exico  to 
initiate  programs  designed  to  improve  the  security 
of  our  shared  borders  and  trans-border  infrastruc¬ 
tures.  Further  global  engagement  is  needed  to 
protect  our  critical  infrastructures  and  key  assets 
from  terrorists.  In  a  world  characterized  by  complex 
interdependencies,  international  cooperation  is  a  key 
component  of  our  protective  scheme. 

7.  D  eve/op  technologies  and  expertise  to  combat 
terrorist  threats 

T  he  N  ational  Strategy  for  H  omeland  Security 
underscores  the  importance  of  science  and 
technology  as  key  elements  of  homeland  security. 

0  ur  efforts  to  secure  critical  infrastructures  and 
key  assets  must  fully  leverage  our  technological 
advantages  to  make  protection  more  effective, 


more  efficient,  and  less  costly.  Pooling  our  national 
resources  and  fostering  collaboration  between  the 
public  and  private  sectors  will  enable  us  to  capitalize 
on  emerging  technologies  and  enhance  our 
protection  against  the  most  lethal  threats. 

Similarly,  through  advances  in  modeling,  simulation, 
and  analysis  we  can  improve  our  understanding  of 
the  complex,  interdependent  nature  of  the  infra¬ 
structures  and  assets  we  must  protect.  E  mergent 
capabilities  in  this  area  will  facilitate  protection 
planning,  decision  making,  and  resource  allocation. 

8.  Safeguard  privacy  and  constitutional  freedoms 

0  ur  society  is  a  tapestry  of  diverse  races,  ethnicities, 
cultures,  religions,  and  political  viewpoints. This 
pluralism  and  our  ability  as  a  society  to  accommo¬ 
date  diversity  significantly  contribute  to  America’s 
strength.  FI  owever,  as  the  N  ational  Strategy  for 
H  omeland  Security  observes,  our  free  society  is  also 
inherently  vulnerable.  N  evertheless,  achieving  secu¬ 
rity  at  the  expense  of  the  civil  rights  and  liberties 
that  form  an  integral  part  of  our  national  character 
would  hand  a  victory  to  terrorism. 

C  onsequently,  we  must  accept  some  level  of  terrorist 
risk  as  a  persisting  condition  in  our  daily  lives. 

The  challenge  is  finding  the  path  that  enables  us 
to  mitigate  risk  and  defend  our  country  while 
preserving  the  freedoms  and  liberties  that  shape 
our  way  of  life.  I  n  providing  for  our  collective 
protection,  we  will  respect  privacy,  the  freedom  of 
expression,  the  freedom  of  movement,  the  freedom 
from  unlawful  discrimination,  and  other  cherished 
liberties  that  define  us  as  a  N  ation. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  13 


14  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


ORGANIZING  AND  PARTNERING 
FOR  CRITICAL  INFRASTRUCTURE 
AND  KEY  ASSET  PROTECTION 


Implementing  a  comprehensive  national  critical 
infrastructure  and  key  asset  protection  strategy  requires 
clear  and  unifying  organization,  clarity  of  purpose, 
common  understanding  of  roles  and  responsibilities, 
accountability,  and  a  set  of  well -understood  coordi¬ 
nating  processes.  A  solid  organizational  scheme  sets 
the  stage  for  effective  engagement  and  interaction 
between  the  public  and  private  sectors.  W  ithout  it, 
accomplishing  the  task  of  coordinating  and  integrating 
domestic  protection  policy,  planning,  resource 
management,  performance  measurement,  and  enabling 
initiatives  across  federal,  state,  and  local  governments, 
and  the  private  sector  would  be  impossible. 

T  he  work  of  providing  a  clearly  defined  and  unifying 
organizational  framework  began  with  the  publication 
of  the  P resident’s  N  ational  Strategy  for  H  omeland 
Security  and  continues  in  this  document.  T  his  chapter 
clarifies  public-  and  private- sector  roles  and  responsi¬ 
bilities  for  critical  infrastructure  and  key  asset 
protection.  U I timately,  success  lies  in  our  ability  to 
draw  effectively  and  efficiently  upon  the  unique  core 
competencies  and  resources  of  each  stakeholder.  G  iven 
the  range  and  complexity  of  required  protection 
activities  and  the  number  of  entities  involved,  clearly- 
defined  authority,  accountability,  and  coordinating 
processes  will  provide  the  foundation  for  a  successful 
and  sustainable  national  protection  effort. 

ORGANIZATION  AND 
PARTNERING  CHALLENGES 

0  verlapping  federal,  state,  and  local  governance  and 
the  ownership  structure  of  our  critical  infrastructures 
and  key  assets  present  significant  protection  challenges. 
T  he  entities  involved  are  diverse,  and  the  level  of 
understanding  of  protection  roles  and  responsibilities 
differs  accordingly.  Furthermore,  these  organizations 
and  individuals  represent  systems,  operations,  and 
institutional  cultures  that  are  complex  and  diverse. 

T  he  range  of  protective  activities  that  each  must 
undertake  is  vast  and  varies  from  one  enterprise  to 
the  next.  Finally,  overlapping  protection  authorities 
across  federal,  state,  and  local  jurisdictions  vary  greatly. 
Success  in  implementing  this  Strategy's  wide  range  of 
protection  activities  lies  in  establishing  a  unifying  orga¬ 
nizational  framework  that  allows  the  development  of 


complementary,  collaborative  relationships  and 
efficiently  aligns  our  N  ation’s  protection  resources. 

CLARIFYING  ROLES 
AND  RESPONSIBILITIES 

I  n  our  federalist  system  of  government,  federal,  state, 
and  local  governments  and  private  industry  have 
specific  roles  and  perform  certain  functions  that  must 
be  integrated  to  assure  protection.  Additionally,  each 
critical  infrastructure  owner/operator  possesses  unique 
capabilities,  expertise,  and  resources  that,  when  inte¬ 
grated  appropriately,  can  contribute  to  a  comprehensive 
national  protection  effort. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  15 


Federal  G  overnment  Responsibilities 

The  federal  government  has  fundamental,  clearly 
defined  responsibilities  under  the  C  onstitution. 
Providing  for  the  common  defense  and  promoting  the 
general  welfare  of  our  country  are  among  them.  T  he 
federal  government  alone  has  the  capability  to  use 
military,  intelligence,  and  diplomatic  assets  to  defend 
A  merica’s  interests  outside  its  borders.  C  loser  to  home, 
with  support  from  state  and  local  governments,  the 
federal  government  has  also  traditionally  led  the  effort 
to  maintain  the  security  of  our  borders.  T o  prevent 
terrorists  from  entering  the  U  .S.,  the  federal  govern¬ 
ment  employs  several  tools  unique  to  its  arsenal, 
including:  military,  diplomatic,  and  intelligence¬ 
gathering  activities;  immigration  and  naturalization 
functions;  and  border  agents,  customs  inspectors, 
and  port  and  air  terminal  security. 

T  he  federal  law  enforcement  apparatus  consists  of 
mechanisms  that  allow  it  to  coordinate  multi- 
jurisdictional  approaches  to  security  threats  and  inci¬ 
dents  and  the  pursuit  of  perpetrators  across  state  lines 
and  overseas.  Additionally,  federal  agencies  conduct 
vital  research  activities,  coordinate  protection  planning 
and  incident  management,  and  provide  material  and 
other  types  of  support  to  state  and  local  authorities. 

T  hese  capabilities  serve  as  elements  of  deterrence, 
prevention,  protection,  and  incident  response. 

Beyond  such  critical  services  and  functions,  the  federal 
government  has  the  capacity  to  organize,  convene,  and 
coordinate  across  governmental  jurisdictions  and  the 
private  sector.  1 1  therefore  has  the  responsibility  to 
develop  coherent  national  policies,  strategies,  and 
programs.  I  n  the  context  of  homeland  security,  the 
federal  government  will  coordinate  the  complementary 
efforts  and  capabilities  of  government  and  private 
institutions  to  raise  our  level  of  protection  over  the 
long  term  for  each  of  our  critical  infrastructures  and 
key  assets. 

E  very  terrorist  event  has  national  impact.  T  he  federal 
government  will  therefore  take  the  lead  to  insure 
that  the  three  principal  objectives  defined  in  the 
Introduction  of  this  Strategy  are  met.  This  leadership 
role  involves: 

•  T aking  stock  of  our  most  critical  facilities,  systems, 
and  functions  and  monitoring  their  preparedness 
across  sectors  and  governmental  jurisdictions; 

•  Assuring  that  federal,  state,  local,  and  private 
entities  work  together  to  protect  critical  facilities, 
systems,  and  functions  that  face  an  imminent  threat 
and/or  or  whose  loss  would  have  significant, 
national- level  consequences; 


•  Providing  and  coordinating  national  threat  assess¬ 
ments  and  warnings  that  are  timely,  actionable,  and 
relevant  to  state,  local,  and  private  sector  partners; 

•  C  reating  and  implementing  comprehensive, 
multi-tiered  protection  policies  and  programs; 

•  Exploring  potential  options  for  enablers  and 
incentives  to  encourage  public-  and- private  sector 
entities  to  devise  solutions  to  their  unique 
protection  impediments; 

•  D  evel oping  protection  standards,  guidelines, 
and  protocols  across  sectors  and  jurisdictions; 

•  Facilitating  the  exchange  of  critical  infrastructure 
and  key  asset  protection  best  practices  and 
vulnerability  assessment  methodologies; 

•  Conducting  demonstration  projects  and  pilot 
programs; 

•  Seeding  the  development  and  transfer  of  advanced 
technologies  while  taking  advantage  of  private 
sector  expertise  and  competencies; 

•  Promoting  national- level  critical  infrastructure  and 
key  asset  protection  education  and  awareness;  and 

•  Improving  its  ability  to  work  with  state  and  local 
responders  and  service  providers  through  partnership. 

A  s  custodian  of  many  of  our  N  ation's  key  assets,  such 
as  some  of  our  most  treasured  icons  and  monuments, 
and  as  the  owner  and  operator  of  mission-critical  facil¬ 
ities,  the  federal  government  also  has  significant,  direct 
protection  responsibilities.  Accordingly,  the  federal 
government  will  take  appropriate  steps  to: 

•  Identify  its  own  critical  facilities,  systems, 
and  functions; 

•  I  dentify  the  critical  nodes  upon  which  these 
assets  depend; 

•  Assess  associated  vulnerabilities;  and 

•  I  mplement  appropriate  steps  to  mitigate  those 
vulnerabilities  and  protect  the  infrastructures  and 
assets  under  its  control. 

F  ederal  L  ead  D  epartments  and  A  gencies 

E  ach  critical  infrastructure  sector  has  unique  security 
chal lenges.  T  he  N  ational  Strategy  for  H  omeland  Security 
provides  a  sector- based  organizational  scheme  for 
protecting  America's  critical  infrastructures  and  key 
assets.  (See Federal  Organization  for  Critical 
Infrastructure  and  Key  Asset  Protection,  p.  18.)  This 
organizational  scheme  identifies  the  federal  lead 
departments  and  agencies  charged  with  coordinating 


16  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


protection  activities  and  cultivating  long-term  collabo¬ 
rative  relationships  with  their  sector  counterparts. 

In  addition  to  securing  federally- owned  and  -operated 
infrastructures  and  assets,  the  roles  of  the  federal  lead 
departments  and  agencies  are  to  assist  state  and  local 
governments  and  private- sector  partners  in  their  efforts  to: 

•  0  rganize  and  conduct  protection  and  continuity 
of  operations  planning,  and  elevate  awareness  and 
understanding  of  threats  and  vulnerabilities  to 
critical  facilities,  systems,  and  functions; 

•  I  dentify  and  promote  effective  sector- specific, 
risk- management  policies  and  protection  practices 
and  methodologies;  and 

•  Expand  voluntary,  protection- related  information 
sharing  among  private  entities  within  sectors,  as 
well  as  between  government  and  private  entities. 

E  ach  federal  lead  department  or  agency  selects  a  "sector 
liaison,"  who  represents  industry’s  primary  interface 
with  the  government.  I  ndustry’s  counterpart,  the  "sector 
coordinator,”  is  designated  by  the  federal  lead  depart¬ 
ment  or  agency  to  serve  as  a  neutral  party  and  facilitate 
sector  coordination  for  a  wide  range  of  planning  and 
activities  to  secure  critical  facilities  and  systems. 

The  federal  government  will  expand  on  this  model  of 
public-private  sector  cooperation  as  a  key  component 
of  our  strategy  for  action.  Accordingly,  the  federal  lead 
departments  and  agencies  of  critical  infrastructure 
sectors  newly  identified  in  the  N ational  Strategy  for 
H  omel and  Security  will  take  immediate  steps  to 
designate  sector  liaisons  and  coordinators  and  initiate 
protection  activities.  This  will  include  identifying 
critical  facilities,  systems,  and  functions  within  their 
sectors  and  facilitating  the  development  of  sector 
protection  plans. 

D  epartment  of  H  omeland  Security 

The  organizational  model  of  federal  lead  departments 
and  agencies  provides  a  focused  leadership  structure  for 
national- level  protection  coordination  and  planning. 

T  he  newly  created  D  epartment  of  H  omeland  Security 
(DH  S)  will  significantly  enhance  the  effectiveness  of 
this  model  by  providing  overall  cross- sector  coordina¬ 
tion.  In  this  role,  D  H  S  will  serve  as  the  primary  liaison 
and  facilitator  for  cooperation  among  federal  depart¬ 
ments  and  agencies,  state  and  local  governments,  and 
the  private  sector. 

As  the  cross- sector  coordinator,  D  H  S  will  also  be 
responsible  for  the  detailed  refinement  and  implemen¬ 
tation  of  the  core  elements  of  this  Strategy.  T  his  charter 
includes  building  and  maintaining  a  complete,  current, 


and  accurate  assessment  of  national- level  critical  assets, 
systems,  and  functions,  as  well  as  assessing  vulnerabili¬ 
ties  and  protective  postures  across  the  critical 
infrastructure  sectors.  DH  S  will  use  this  information  to 
assess  threats,  provide  timely  warnings  to  threatened 
infrastructures,  and  build  "red  team"  capabilities  to 
evaluate  preparedness  across  sectors  and  government 
jurisdictions.  Furthermore,  D  H  S  will  collaborate  with 
other  federal  departments  and  agencies,  state  and  local 
governments,  and  the  private  sector  to  define  and 
implement  complementary  structures  and  coordination 
processes  for  critical  infrastructure  and  key  asset  protec¬ 
tion.  An  effective  starting  point  for  this  effort  is  the 
approach  presently  employed  by  federal  lead  depart¬ 
ments  and  agencies  and  state  and  local  governments  to 
cooperate  when  responding  to  natural  disasters. 

In  addition  to  cross- sector  coordination,  D  H  S  will 
act  as  the  federal  lead  department  for  several  sectors, 
including  government,  emergency  response,  transporta¬ 
tion,  postal  and  shipping,  and  information  and 
telecommunications. 

To  fulfill  these  responsibilities,  D  H  S  will: 

Build  partnerships  with  stateand  local  governmentsand 
the  private  sector  by  designing  and  implementing  its  own 
processes  to  be  open,  indusive,  and  results-  oriented. 

•  Actively  develop  opportunities  to  build  upon 
proven  models; 

•  I  dentify  and  share  the  federal  government's  core 
competencies,  capabilities,  and  selected  resources  to 
enhance  the  efforts  of  its  partners;  and 

•  Facilitate  honest  brokering  and  communication 
between  organizations  and  sectors. 

0  ffice  of  H  omeland  Security 

The  Office  of  H  omeland  Security  (0  H  S)  will 
continue  to  act  as  the  President’s  principal  policy  advi¬ 
sory  staff  and  coordinating  body  for  major  interagency 
policy  issues  related  to  H  omeland  Security,  including 
the  critical  infrastructure  and  key  asset  protection 
mission  area.  The  functions  of  OH  S  will  be  to  advise 
and  assist  the  President  in  the  coordination  of  the 
E  xecutive  Branch's  efforts  to  detect,  prepare  for, 
prevent,  protect  against,  respond  to,  and  recover  from 
terrorist  attacks  within  the  U  nited  States.  OHS  will 
work  with  the  Office  of  M  anagement  and  Budget 
(0  M  B)  to  integrate  and  endorse  the  President’s 
critical  infrastructure  and  key  asset  protection  budget 
proposals.  U  nder  its  existing  authority,  OHS  will  also 
work  with  0  M  B  to  certify  that  the  budgets  of  other 
federal  departments  and  agencies  are  sufficient  to  carry 
out  their  respective  protection  missions  effectively. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  17 


FEDERAL  GOVERNMENT  ORGANIZATION  TO 

PROTECT  CRITICAL  INFRASTRUCTURE  AND  KEY  ASSETS 

President 

Secretary  of  H  omeland  Security 

Federal,  state,  local,  and  private  sector  coordination  and  integration 

Comprehensive  national  infrastructure  protection  plan 

M  apping  threats  to  vulnerabilities  and  issuing  warnings 

1 

1 

Sector 

Lead  Agency 

Agriculture 

D  epartment  of  A  gri culture 

Food: 

M  eat  and  poultry 
A II  other  food  products 

D  epartment  of  A  gri  culture 

D  epartment  of  FI  ealth  &  FI  uman  Services 

Water 

Environmental  Protection  Agency 

Public  FI  ealth 

D  epartment  of  FI  ealth  &  FI  uman  Services 

E  mergency  Services 

Department  of  FI  omeland  Security 

G  overnment: 
Continuity  of  government 
C  ontinuity  of  operations 

D  epartment  of  FI  omeland  Security 

All  departments  and  agencies 

Defense  1  ndustrial  Base 

D  epartment  of  D  efense 

1  nformation  and  T elecommunications 

Department  of  FI  omeland  Security 

E  nergy 

D  epartment  of  E  nergy 

Transportation 

D  epartment  of  FI  omeland  Security* 

Banking  and  Finance 

D  epartment  of  the  T  reasury 

C  hemical  1  ndustry  and  FI  azardous  M  aterials 

Environmental  Protection  Agency 

Postal  and  Shipping 

Department  of  FI  omeland  Security 

National  M  onumentsand  Icons 

D  epartment  of  the  1  nterior 

*  U  nder  the  Homeland  Security  Act  of  2002,  the  Transportation  Security  Administration,  responsible  for  securing  our  N  ation's  trans¬ 
portation  systems,  will  become  part  of  the  D  epartment  of  H  omeland  Security.  T  he  new  D  epartment  will  coordinate  closely  with  the 
Department  of  Transportation,  which  will  remain  responsible  for  transportation  safety. 

18  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


Other  Federal  D  epartments and  Agencies 

Besides  the  designated  federal  lead  departments  and 
agencies,  the  federal  government  will  integrate  the 
unique  expertise  and  skill  sets  of  numerous  other 
departments  and  agencies  to  enhance  the  physical 
protection  dimension  of  homeland  security.  For 
example,  the  N  ational  I  nstitute  of  Science  and 
T echnology’s  (N  I  ST 's)  N  ational  Standards  and 
M  easurements  Laboratory  will  play  a  significant  role  in 
standards- setting  for  the  critical  infrastructure  and  key 
asset  protection  mission.  Recent  examples  of  this  role 
are  reflected  in  the  language  of  the  USA  Patriot  Act 
of  2001,  E  nhanced  Border  Security  and  Visa  R  eformAct 
of  2002,  and  N  ational  C  onstruction  Safety  T earn  A  ct. 

Overall  sector  initiatives  will  often  comprise  interna¬ 
tional  components,  require  the  development  of 
coordinated  relationships  with  foreign  governments  or 
agencies,  and  entail  information  sharing  with  foreign 
governments.  Accordingly,  the  D  epartment  of  State 
(DoS)  will  support  the  development  and  implementa¬ 
tion  of  protection  initiatives  by  laying  the  groundwork 
for  bilateral  and  multilateral  infrastructure  protective 
agreements  with  our  international  friends  and  allies. 
Through  its  unique  responsibility  to  lead  U.S.  foreign 
policy  and  support  the  programs  and  efforts  of  other 
federal  departments  and  agencies,  D  oS  will  play  a  key 
role  in  advancing  our  critical  infrastructure  and  key 
asset  priorities. 

State  and  L  ocal  G  overnment  Responsibilities 

The  50  states,  4  territories,  and  87,000  local  jurisdic¬ 
tions  that  comprise  this  N  ation  have  an  important  and 
unique  role  to  play  in  the  protection  of  our  critical 
infrastructures  and  key  assets.  All  U .S.  states  and  terri¬ 
tories  have  established  homeland  security  liaison  offices 
to  manage  their  counter-terrorism  and  infrastructure 
protection  efforts.  I  n  addition,  the  states  have  law 
enforcement  agencies,  N  ational  G  uard  units,  and  other 
critical  services  that  can  be  employed  to  protect 
their  communities. 

Like  the  federal  government,  states  should  identify  and 
secure  the  critical  infrastructures  and  key  assets  under 
their  control.  W  ith  the  support  of  federal  lead  depart¬ 
ments  and  agencies,  states  should  also  promote  the 
coordination  of  protective  and  emergency  response 
activities  and  resource  support  among  local  jurisdic¬ 
tions  and  between  regional  partners.  States  should 
further  facilitate  coordinated  planning  and  prepared¬ 
ness  by  applying  unified  criteria  for  determining 
criticality,  prioritizing  protection  investments,  and 
exercising  preparedness  within  their  jurisdictions.  They 
should  also  act  as  conduits  for  requests  for  federal 
assistance  when  the  threat  at  hand  exceeds  the 


capabilities  of  state  and  local  jurisdictions  and  the 
private  entities  within  them.  States  should  also  facili¬ 
tate  the  exchange  of  relevant  security  information  and 
threat  alerts  down  to  the  local  level. 

M  any  states  have  well-organized  relationships  with 
one  another  through  various  organizations,  such  as  the 
N  ational  E  mergency  M  an agers  Association  and  the 
National  Governors  Association,  as  well  as  through 
mutual  support  agreements.  Coordinating  with  one 
another,  they  can  capitalize  on  their  mutual  capabilities 
through  regional  approaches  to  protection.  As  proven 
during  September  11  response  efforts,  mutual  aid 
agreements  and  other  such  successful  cooperative 
processes  for  crisis  management  demonstrate  the 
competence  of  various  jurisdictions  and  organizations 
to  plan  and  work  together. 

At  the  onset,  every  disruption  or  attack  is  a  local 
problem.  Regardless  of  who  owns  and  operates  the 
affected  infrastructure,  each  requires  an  immediate 
response  by  local  authorities  and  communities  who 
must  support  the  initial  burden  of  action  before  the 
incident  escalates  to  a  national  event. 

L  ocal  governments  represent  the  front  lines  of  protec¬ 
tion  and  the  face  of  public  services  to  the  A  merican 
people.  T  heir  core  competencies  must  include  knowl¬ 
edge  of  their  communities,  residents,  landscapes,  and 
existing  critical  services  for  maintaining  public  health, 
safety,  and  order.  Communities  look  to  local  leadership 
to  assure  safety,  economic  opportunities,  and  quality  of 
life.  Public  confidence,  therefore,  starts  locally  and  is 
dependent  upon  how  well  communities  plan  and  are 
able  to  protect  their  citizens,  respond  to  emergencies, 
and  establish  order  from  chaos.  W  hen  local  authorities 
succeed  in  preventing  or  mitigating  loss  of  life  or  prop¬ 
erty,  or,  as  in  N  ew  York  C  ity  on  September  11,  respond 
to  disaster  with  clarity  of  purpose  and  effectiveness, 
they  affirm  their  capabilities  and  bolster  public  confi¬ 
dence.  For  this  reason,  local  communities  play  critical 
roles  in  preparing  their  citizens  for  emergencies  and 
engaging  their  public  and  private  leadership  in  the 
development  of  coordinated  local  and  regional  plans 
to  assure  the  protection  of  residents  and  businesses. 

State  and  local  governments  look  to  the  federal 
government  for  support  and  resources  when  national 
requirements  exceed  their  capabilities  to  fulfill  them. 
Protecting  critical  infrastructures  and  key  assets  will 
require  a  particularly  close  and  well-organized 
partnership  among  all  levels  of  government.  D  FI  S,  in 
particular,  will  provide  a  single  point  of  coordination 
for  state  and  local  governments  for  homeland  security 
issues.  Other  federal  lead  departments  and  agencies 
and  federal  law  enforcement  organizations  will  provide 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  19 


support  as  needed  and  appropriate  for  specific  critical 
infrastructure  and  key  asset  protection  issues. 

Private- Sector  Responsibilities 

T  he  lion’s  share  of  our  critical  infrastructures  and  key 
assets  are  owned  and  operated  by  the  private  sector. 

C  ustomarily,  private  companies  prudently  engage  in 
risk  management  planning. They  also  invest  in  security 
as  a  necessary  component  of  their  business  operations 
and  to  assure  customer  confidence.  I  n  the  present 
threat  environment,  the  private  sector  remains  the  first 
line  of  defense  for  its  own  facilities.  Consequently, 
private- sector  owners  and  operators  should  reassess 
and  adjust  their  planning,  assurance,  and  investment 
programs  to  accommodate  the  increased  risk  presented 
by  deliberate  acts  of  terrorism.  Since  the  events  of 
September  11,  enterprises  nationwide  have  increased 
their  investments  in  security  to  meet  the  demands  of 
the  new  threat  environment. 

For  most  enterprises,  the  level  of  security  investment 
they  undertake  reflects  implicit  risk-versus- conse¬ 
quence  tradeoffs,  which  are  determined  based  on: 

(1)  what  is  known  about  the  risk  environment, 
and  (2)  what  is  economically  justifiable  and  sustainable 
in  a  competitive  marketplace  or  in  an  environment 
of  limited  resources.  G  iven  the  dynamic  nature  of  the 
terrorist  threat  and  the  severity  of  the  potential 
consequences  associated  with  many  potential  attack 
scenarios,  the  private  sector  will  look  to  the 
government  to  help  better  inform  its  crucial  security 
investment  decisions.  Similarly,  the  private  sector  will 
require  assistance  when  the  threat  exceeds  an  enter¬ 
prise’s  capability  to  protect  itself  beyond  a  reasonable 
level  of  security  investment.  T  he  federal  government 
will  collaborate  with  public-  and  private- sector 
entities  to  assure  the  protection  of  nationally  critical 
infrastructures  and  assets,  provide  timely  warnings  and 
help  assure  the  protection  of  infrastructures  that  are 
specifically  threatened,  and  promote  an  environment  in 
which  the  private  sector  can  better  carry  out  its  specific 
protection  responsibilities. 

The  availability  of  both  timely,  credible  information  and 
relevant  expertise,  complemented  by  inclusive  access  to 
affordable  tools  and  best  practices,  encourages  the 
private  sector  to  make  prudent  investments  earlier  and 
at  all  levels  of  the  risk  management  spectrum.  By 
developing  mutually  beneficial  relationships  and  coordi¬ 
nating  protection  efforts,  public-private  partnership 
can  significantly  enhance  our  N  ation's  ability  to  protect 
its  critical  infrastructures  and  key  assets. 

Working  with  D  FI  S  and  other  federal  lead  departments 
and  agencies,  sector  coordinators  will  play  a  crucial  role 


in  enabling  this  collaboration.  Sector  coordinators  will 
also  work  with  the  government  to  identify,  promote, 
and  share  industry- specific  best  practices.  To  fulfill  their 
protection  agendas,  sector  coordinators  will  rely  on 
D  FI  S  and  other  federal  lead  departments  and  agencies 
to  provide  consistent  guidance  and  criteria  for  sector- 
specific  protection  planning  and  investment  as  well  as 
for  relevant,  actionable,  and  timely  indications  and 
warnings.  T  he  private  sector  may  also  require  incentives 
to  stimulate  investment.  Accordingly,  sector  liaisons  and 
sector  coordinators  will  work  with  their  counterparts  to 
explore  potential  catalysts  and  reduce  the  barriers  to 
public- private  sector  cooperation. 

I  n  addition  to  formal  government  support,  private 
industry  can  take  many  steps  to  improve  its  own  security 
posture  across  the  board.  M  any  industries  have  devel¬ 
oped  alliances  to  sustain  reliability  and  assure  public 
confidence  in  their  national- level  infrastructures. 

Because  the  public’s  perception  of  a  sector’s  overall 
performance  can  affect  the  shareholder  values  of  its 
individual  members,  many  institutions  cooperate  within 
a  framework  for  sharing  operational  and  security- related 
best  practices.  Sectors  whose  constituent  enterprises  are 
highly  interconnected  have  also  developed  mutual  aid 
agreements  to  prevent  the  disruption  of  one  member’s 
systems  from  cascading  to  others  across  the  sector. 
Reliability  activities  of  the  energy  sector,  specifically  the 
electricity  industry,  are  an  example  of  an  effective  critical 
infrastructure  partnership. 

Even  before  the  September  11  attacks,  several  critical 
infrastructure  industries  had  already  established 
Information  Sharing  and  Analysis  Centers  (ISACs)  to 
formalize  information  exchange  among  their  members 
and  improve  the  management  of  operational  risks  from 
physical  and  cyber  disruption.  M  oreover,  many  sector 
organizations,  working  with  their  federal  counterparts, 
have  also  developed  plans  to  contribute  to  the  national 
protection  effort.  Federal  support  of  sector  ISACs  and 
protection  planning  must  now  expand  to  include  the 
newly  designated  critical  infrastructure  sectors. 

Partnership  will  provide  the  foundation  for  developing 
and  implementing  coordinated  protection  strategies. 

T rue  partnerships  require  continuous  interaction  and, 
above  all,  trust.  C  urrently,  however,  there  are  barriers 
impeding  the  public  and  private  sectors  from  achieving 
a  relationship  of  this  level.  M  any  current  attitudes  and 
institutional  relationships,  processes,  and  structures  are 
products  of  a  bygone  era.  Safeguarding  our  critical 
infrastructures  and  key  assets  from  terrorism  in  today’s 
fluid  marketplace  and  threat  environment  requires  a 
new,  more  cooperative  set  of  institutional  relationships 
and  attitudes.  The  need  for  partnering  is  clear. 


20  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


CROSS-SECTOR 

SECURITY  PRIORITIES 


T  his  chapter  addresses  the  overarching,  cross- sector 
initiatives  that  represent  our  national-level  priorities  for 
critical  infrastructure  and  key  asset  protection.  T  he 
focus  is  on  cross- sector  protection  issues  and  activities 
that  require  immediate  attention,  encourage  coopera¬ 
tion,  and  increase  the  cost-effectiveness  of  security 
investments.  The  protection  initiatives  outlined  herein 
also  support  the  three  underlying  objectives  of  this 
Strategy:  (1)  identifying  and  assuring  the  protection  of 
our  most  nationally  critical  infrastructures  and  assets; 

(2)  providing  timely  warning  and  assuring  the  protec¬ 
tion  of  infrastructures  and  assets  that  face  a  specific, 
imminent  threat;  and  (3)  fostering  an  environment  in 
which  all  stakeholders  can  better  protect  the  infrastruc¬ 
tures  and  assets  under  their  control. 

We  have  entered  a  fluid  threat  environment  in  which 
security  must  be  viewed  as  an  integral  component  of 
core  practices  and  standard  operations—  not  a  box  to 
be  checked  before  addressing  other  issues.  A  s  the 
threat  of  terrorism  persists  and  evolves,  we  must  be 


able  to  adapt  our  security  planning  and  protection 
efforts  to  remain  effective  and  sustainable  over  the  long 
term.  The  activities  that  follow  in  this  Strategy 
represent  the  first  steps  in  this  national  journey. 

T  he  cross- sector  security  initiatives  addressed  in  this 
chapter  fall  into  the  following  categories: 

•  Planning  and  Resource  Allocation 

•  Information  Sharing  and  Indications  and  Warnings 

•  Personnel  Surety,  Building  H  uman  Capital,  and 
Awareness 

•  Technology  and  Research  &  Development 

•  M  odeling,  Simulation,  and  Analysis 

E  ach  section  describes  a  cross- sector  protection  issue  as 
well  as  the  impediments  to  protection  associated  with  that 
issue.  It  then  identifies  specific  actions  that  will  betaken 
to  address  those  challenges  and  remove  barriers  hindering 
the  implementation  of  needed  protection  activities. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  21 


PLANNING  AND  RESOURCE  ALLOCATION 


Effective  and  efficient  risk  assessment,  protection 
planning,  and  resource  allocation  go  hand  in  hand. 

T  hey  depend  upon  the  ability  of  federal,  state,  and  local 
governments,  the  private  sector,  and  our  international 
partners  to  work  together  to  articulate  and  attain  their 
individual  and  shared  goals,  requirements,  and  priorities. 

State  and  local  governments  currently  face  unprece¬ 
dented  demands  for  their  limited  resources.  D  eclines  in 
revenues  mean  that  states  and  local  communities  often 
lack  the  resources  to  undertake  a  full  spectrum  of 
prudent  critical  infrastructure  protection  measures. 
Because  of  these  resource  limitations,  federal,  state, 
and  local  authorities  must  collaborate  more  efficiently 
to  assess,  plan,  and  allocate  their  limited  resources. 

Industry  is  likewise  coping  with  the  consequences  of 
dynamic  threats  and  difficult  economic  environments. 

I  n  some  cases,  certain  critical -sector  enterprises  are 
concentrating  their  resources  solely  on  remaining  in 
business.  To  instill  greater  stability  in  the  security 
investment  process,  it  will  be  necessary  for  private- 
sector  organizations  to  closely  coordinate  critical 
infrastructure  protection  plans  and  programs  to  ensure 
that  federal  and  state  governments,  in  particular,  under¬ 
stand  and  recognize  their  future  spending  landscape. 

Risk  assessment  and  management  must  also  be  closely 
integrated  and  coordinated.  Industries  and  institutions 
are  in  need  of  a  common  vocabulary  and  standards  to 
guide  their  protection  efforts.  C  lose  cooperation 
among  all  levels  of  government  and  the  private  sector 
both  nationally  and  internationally  is  essential  to  devel¬ 
oping  a  shared  vernacular  and  vision  for  the  future. 


Planning  and  Resource  Allocation  C  hallenges 

H  eavy  demands  on  state  and  local  resources, 
uncertainties  created  by  a  lack  of  coordination,  and 
dynamics  of  the  terrorist  threat  underlie  many  of  the 
challenges  of  the  domestic  protection  environment. 
Since  the  September  11  attacks,  state  and  local  govern¬ 
ments  have  been  called  upon  to  provide  increased 
security  for  their  critical  infrastructures  and  key  assets, 
border  areas,  airports,  and  seaports.  U  nanticipated 
revenue  declines  have  affected  most  states  and  chal¬ 
lenged  their  abilities  to  meet  the  requirements  of 
operating  under  balanced  budgets.  H  ence,  they  cannot 
increase  expenditures  to  account  for  additional 
protective  measures  without  making  corresponding 
reductions  in  spending  for  other  programs  and  services. 

W  e  often  rely  on  state  and  local  jurisdictions  to  protect 
key  national  assets  (e.g.,  bridges,  tunnels,  nuclear  power 
plants,  dams,  and  airports).  C  onversely,  state  and  local 
governments  request  federal  resources  at  times  to  ensure 
the  protection  of  their  own  critical  infrastructures  and 
key  assets.  Under  uncertain  and  sustained  elevated 
threat  conditions,  determining  how  best  to  allocate  the 
scarce  resources  of  the  various  jurisdictions  responsibly 
and  appropriately  will  require  unprecedented  levels  of 
cooperation  across  all  levels  of  government. 

Another  resource  allocation  challenge  relates  to  the 
mechanisms  through  which  states  must  apply  for 
federal  assistance.  Current  policies  and  procedures 
sometimes  create  inefficiencies  in  the  federal  grant 
decision-making  process.  Because  they  must  seek 
funding  from  various  sources  according  to  different 
guidelines,  state  and  local  government  officials  often 
view  complying  with  grant  requirements  and  review 
processes  as  leading  to  duplications  of  effort. 

Rectifying  the  lack  of  streamlined  mechanisms  for 
providing  federal  funding  to  state  and  local  govern¬ 
ments  will  require  a  thorough  cross- agency  review. 

E  ngaging  U.S.  states  and  territories  in  a  collaborative 
framework  for  infrastructure  protection  is  another 
important  planning  challenge.  State  and  local  law 
enforcement  agencies  and  emergency  responders  are 
the  first  line  of  defense  against  deliberate  acts  of 
violence.  In  fact,  state  and  local  jurisdictions  continue 
to  bear  a  large  share  of  post- September  11  security 
expenditures  nationwide.  T  heir  concerns  and 
constraints  must  be  recognized  and  factored  into  our 
national  protective  scheme. 


22  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


A  key  challenge  in  prioritizing  efforts  to  enhance 
infrastructure  protection  is  the  difficulty  in  estimating 
the  economic  damage  that  could  result  from  a  terrorist 
attack.  Such  damage  includes  both  the  immediate 
effects  of  a  strike  (e.g.,  losses  to  plant  and  equipment) 
as  well  as  any  subsequent  long-term  economic  losses. 

T  he  cascading  effects  often  overshadow  short-term 
repercussions  over  time,  yet  they  are  extremely  difficult 
to  estimate.  Relatively  short-term  disruptions  to  critical 
operations  can  produce  significant  downstream 
economic  effects  (e.g.,  price  changes,  lost  contracts, 
lost  financing,  and  losses  in  insurability).  Predicting 
the  extent  of  such  effects  accurately  requires  acute 
sensitivity  to  the  myriad  of  interdependencies  present 
in  modern  industrial  and  financial  markets. 

I  n  the  risk  management  process,  certain  aspects  of 
criticality  determination  may  also  produce  inadvertent 
consequences.  Designating  certain  facilities  as  "critical" 
in  conjunction  with  domestic  protection  efforts  may 
result  in  their  becoming  more  difficult  and  expensive  to 
insure  and  operate.  T  he  federal  government  must  work 
in  concert  with  other  key  stakeholders  to  explore 
options  for  incentives  to  compensate  for  the  costs 
engendered  by  the  current  threat  environment. 

A  ligning  disparate  assessment  methodologies  presents 
another  challenge.  Presently,  multiple  methodologies 
from  various  departments  and  agencies  are  currently 
being  used  to  assess  vulnerabilities.  I  n  many  cases,  they 
are  neither  consistent,  nor  comparable,  thereby  compli¬ 
cating  protection  planning  and  resource  allocation 
across  the  board. 

M  any  critical  infrastructures  also  cross  international 
borders,  raising  unique  protection  challenges.  We 
must,  therefore,  work  closely  with  our  friends  and 
allies  around  the  world  to  develop  plans  to  secure  the 
interconnected  infrastructures  that  make  up  the 
international  marketplace. 

Planning  and  Resource  Allocation  Initiatives 

It  is  incumbent  in  the  planning  and  resource  allocation 
process  that  federal,  state,  and  local  governments  and 
private- sector  stakeholders  work  together  to: 

•  D  efine  clearly  their  critical  infrastructure  and  key 
asset  protection  objectives; 

•  D  evelop  a  business  case  for  action  to  justify 
increased  security  investments; 

•  Establish  security  baselines,  standards,  and 
guidelines;  and 

•  Identify  potential  incentives  for  security- related 
activities  where  they  do  not  naturally  exist  in 
the  marketplace. 


To  enable  such  actions,  we  will: 

C  reate  collaborative  mechanisms  for  public-  and 
private'  sector  critical  infrastructure  and  key  asset 
protection  planning 

D  H  S  and  other  federal  lead  departments  and 
agencies  will  enable  and  encourage  the  development 
of  clearly  defined  collaborative  mechanisms  through 
which  the  public  and  private  sectors  can  cooperate 
in  national -level  protection  planning  and  perform¬ 
ance  measurement.  T  he  federal  government  will  also 
work  in  conjunction  with  other  stakeholders  to 
assess  critical  infrastructure  and  asset  vulnerabilities, 
share  information,  develop  protection  strategies  and 
plans  to  eliminate  or  mitigate  these  vulnerabilities, 
and  develop  restoration  and  recovery  plans  for 
implementation  in  the  aftermath  of  an  attack.  D  H  S 
will  assess  these  sector  plans  for  clarity,  comprehen¬ 
siveness,  consistency,  and  resource  prioritization. 

D  H  S  will  also  assimilate  the  individual  sector  plans 
into  a  comprehensive  national  plan  for  critical 
infrastructure  and  key  asset  protection  to  inform 
the  federal  government's  annual  process  of  planning, 
programming,  and  budgeting  for  national-level 
protection  activities. 

I  dentify  key  protection  prioritiesand  develop  appropriate 
supporting  mechanisms  for  these  priorities 

D  H  S,  in  collaboration  with  other  key  stakeholders, 
will  develop  a  uniform  methodology  for  identifying 
facilities,  systems,  and  functions  with  national- level 
criticality  to  help  establish  federal,  state,  and  local 
government  and  the  private- sector  protection  prior¬ 
ities.  Using  this  methodology,  D  H  S  will  build  a 
comprehensive  database  to  catalog  these  critical 
facilities,  systems,  and  functions.  D  H  S  will  also 
maintain  a  comprehensive,  up-to-date  assessment 
of  vulnerabilities  and  preparedness  across  critical 
sectors.  T  his  effort  will  help  guide  near-term 
protective  actions  and  provide  a  basis  for  long-term 
leadership  focus  and  informed  resource  investment. 

D  H  S  will  furthermore  establish  a  multi-year 
approach  for  critical  infrastructure  and  key  asset 
protection  to  instill  predictability  and  structure 
in  the  planning  process. 

Foster  increased  sharing  of  risk-  management  expertise 
between  the  public  and  private  sectors 

M  any  different  risk  assessment  methodologies  are 
in  use  based  on  a  wide  variety  of  requirements  and 
standards.  G  overnment  and  industry  could  each 
benefit  greatly  from  the  extensive  experience  of  the 
other.  D  H  S  will  coordinate  the  sharing  of  lessons 
learned  and  best  practices  to  build  a  common 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  23 


domestic  protection  assessment  framework  that  is 
adaptable  to  different  user  environments. 

I  dentify  options  for  incentives  for  private  organizations 
that  proactively  implement  enhanced  security  measures 

Consulting  with  the  private  sector,  D  H  S  will  work 
with  the  D  epartment  of  C  ommerce  (D  oC )  and 
the  D  epartment  of  the  Treasury  to  identify 
appropriate  options  for  developing  cost-effective 
incentives  to  compensate  stakeholders  for  enhanced 
security  investments. 

This  could  include  rewarding  early  adopters  of  new 
policies  or  providing  various  incentives  for  incorpo¬ 
rating  security  enhancements  into  critical  sector 
products  and  services. 

C  oordinate  and  consolidate  federal  and  state 
protection  plans 

D  H  S  will  work  with  other  federal  departments  and 
agencies  to  consolidate  federal  protection  plans  to 
clarify  roles,  responsibilities,  and  expectations.  D  H  S 
will  also  work  with  the  states  to  coordinate  protec¬ 
tion-planning  efforts  and  provide  them  with  a  clear 
roadmap  for  action.  Additionally,  the  H  omeland 
Security  Advisory  System  will  be  coordinated  with 
state-level  critical  infrastructure  and  key  asset 
protection  plans. 

E  stablish  a  taskforce  to  review  legal  impediments  to 
reconstitution  and  recovery  following  an  attack  against  a 
critical  infrastructure  or  key  asset 

D  H  S,  in  concert  with  the  D  epartment  of  Justice 
(D  oj),  will  convene  representatives  from  federal, 
state,  and  local  governments,  and  the  private  sector 
to  scrutinize  regulatory  and  licensing  procedures 
that  could  impede  reconstitution  of  critical  infra¬ 
structure  service  in  emergencies  and  identify  options 
for  resolving  them. 

Reconstitution  requirements  for  critical  infrastruc¬ 
tures  may  necessitate  the  waiving  of  established 
licensing  and  regulatory  procedures  during 


emergencies.  Procedures  for  establishing  these  "post 
incident  rule  sets"  need  to  be  predetermined  as  part 
of  part  of  a  collaborative  public- private  partnership. 

D  evelop  an  integrated  critical  infrastructure  and  key  asset 

geospatial  database 

T o  enable  effective  critical  infrastructure  and  key 
asset  protection  planning,  analysis,  and  decision 
support,  we  must  develop  an  integrated  critical 
infrastructure  and  key  asset  geospatial  database  for 
access  and  specific  use  by  federal,  state,  and  local 
government  officials,  and  the  private  sector. 

A  geospatial  assurance  partnership  of  appropriate 
government  departments  and  agencies  is  needed  to 
serve  as  the  imagery/geospatial  data  broker,  inte¬ 
grator,  and  coordinator  for  this  database.  D  H  S  and 
other  federal  departments  and  agencies  will 
continue  current  efforts  to  acquire  data  for  priority 
population  centers,  domestic  critical  infrastructure 
sectors,  and  transborder  infrastructures  in  coopera¬ 
tion  with  the  private  sector.  This  database  will 
provide  a  common  frame  of  reference  for  senior 
public-  and  private- sector  decision  makers  and 
operational  planners  in  support  of  vulnerability 
analysis,  domestic  preparedness,  and  incident 
management. 

Conduct  critical  infrastructure  protection  planning  with 

our  international  partners 

I  n  the  aftermath  of  the  September  11  attacks,  we 
developed  comprehensive  bilateral  critical  infrastruc¬ 
ture  protection  framework  agreements  and  began  a 
series  of  protection  initiatives  with  our  Canadian  and 
M  exican  neighbors.  D  H  S,  in  concert  with  D  oS  and 
other  federal  departments  and  agencies  will  work  to 
expand  this  security  collaboration  to  include  other 
key  international  partners. The  overall  objective  of 
this  effort  will  be  to  determine  our  transborder  infra¬ 
structure  vulnerabilities  and  implement  measures  to 
el  i  m i  n ate  or  m i  ti  gate  th ese  vu I  n erabi  I  i t i  es. 


24  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


INFORMATION  SHARING  AND 
INDICATIONS  AND  WARNINGS 


T o  meet  the  challenges  associated  with  the  terrorist 
threat,  public-  and  private-sector  critical  infrastructure 
and  key  asset  protection  stakeholders  must  have  the 
ability  to  work  together  seamlessly.  T  he  federal 
government—  particularly  the  intelligence  and  law 
enforcement  communities—  has  a  significant  role  in 
providing,  coordinating,  and  ensuring  that  threat  infor¬ 
mation  is  understood  across  all  levels  of  government. 
Likewise,  state  and  local  law  enforcement  and  private- 
sector  security  entities  are  also  valuable  sources  of 
localized  threat  information.  Additionally,  they  possess 
a  much  better  understanding  of  the  vulnerabilities 
impacting  their  facilities,  systems,  and  functions  than 
does  the  federal  government.  D  evelopment  of  accepted 
and  efficient  processes  and  systems  for  communication 
and  exchange  of  crucial  security- related  information 
is  critical  to  bridging  existing  gaps  and  building  a 
foundation  for  cooperation. 


The  difficulties  and  roadblocks  routinely  faced  by  those 
attempting  to  share  security  information  serve  as  major 
impediments  to  progress  in  the  critical  infrastructure 
and  key  asset  protection  mission  area.  An  extraordinary 
level  of  cooperation  and  perseverance  will  be  required 
to  change  the  status  quo.  Federal,  state,  and  local 
governments  and  the  private  sector  must  make  every 
effort  to  promote  effective  information  sharing  and 
embrace  efforts  to  establish  timely,  effective,  and  useful 
paths  of  communication  between  those  who  need  it 
most.  Information  is  a  crucial  tool  in  fighting 
terrorism,  and  getting  the  right  information  to  the 
right  party  at  the  right  time  is  a  top  priority. 

Adequate  protection  of  our  critical  infrastructures  and 
key  assets  requires: 

•  Improved  collection  of  threat  information; 

•  C  omprehensive  and  relevant  threat  assessment 
and  analysis; 

•  Robust  indications  and  warning  processes  and 
systems;  and 

•  Improved  coordination  of  information  sharing 
activities. 

Accurate,  timely  information  is  a  fundamental  element 
of  our  national  critical  infrastructure  and  key  asset 
protection  effort.  It  underpins  all  components  of  our 
protection  strategy  and  enables  preventive  action, 
warning,  preparation,  and  crisis  response.  Presently, 
major  impediments  exist  to  accomplishing  effective 


information  sharing  among  all  levels  of  the  public  and 
private  sectors.  0  vercoming  these  obstacles  entails: 

•  Identifying  what  is  to  be  accomplished  by 
exchanging  security- related  information; 

•  Defining  the  type  of  information  that  must  be 
shared  to  accomplish  that  purpose; 

•  D  etermining  how  and  when  to  share  and  safeguard 
critical  security  information  most  properly; 

•  D  eciding  who  the  appropriate  recipients  of  such 
information  will  be; 

•  Assigning  responsibility  for  analyzing  information 
and  determining  the  threat  implications;  and 

•  Assigning  responsibility  for  appropriate  action  once 
that  information  has  been  analyzed  and  the  threat 
implications  are  clear. 

I  nformation  Sharing  and  I  ndications 
and  W  arnings  C  hallenges 

The  overall  management  of  information  sharing 
activities  among  government  agencies  and  between  the 
public  and  private  sectors  has  lacked  proper  coordination 
and  facilitation.  As  a  result,  the  existing  national  mecha¬ 
nisms  for  collecting  threat  information,  conducting  risk 
analyses,  and  disseminating  warnings  have  been 
inadequate  for  the  domestic  protection  mission. 

State  and  local  governments  and  private  sector  officials 
have  indicated  that  the  threat  information  they  receive 
from  the  federal  government  is  often  vague,  duplicative, 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  25 


and—  in  some  cases—  conflicting.  T  hey  argue  that  they 
seldom  receive  indications  and  warnings  that  are 
specific,  accurate,  and  timely  enough  to  support  difficult 
resource  allocation  decisions.  Conversely,  when  relevant, 
timely  information  is  shared,  they  point  out  that  it  often 
fails  to  reach  the  appropriate  parties  because  of  security 
clearance  requirements. 

Additionally,  the  current  security  clearance  process  is 
redundant  and  costly,  with  lengthy  delays.  I  n  one 
example,  current  regulations  require  certain  state  and 
local  law  enforcement  officials  to  be  screened  twice,  once 
by  state  and  local  authorities  and  again  by  the  federal 
government.  We  must  streamline  this  process  to  make  it 
more  responsive  to  our  protection  needs. 

I  n  fact,  protecting  the  N  ation’s  critical  infrastructures 
and  key  assets  may  not  necessarily  require  such  clear¬ 
ance  for  all  stakeholders.  If  intelligence  sources  and 
methods  are  omitted,  many  intelligence  reports  may  be 
declassified.  T  ime- efficient  procedures  are  needed  to 
declassify  relevant  intelligence  or  extract  information 
from  classified  sources  and  disseminate  that  informa¬ 
tion  to  the  appropriate  recipients.  T  hese  concerns  are 
complicated  by  the  ineffective  means  by  which  sensitive 
information  is  transferred,  as  well  as  the  mechanisms 
currently  in  place  to  ensure  that  required  information  is 
disseminated  appropriately.  C  urrently,  there  is  no 
central,  coordinating  mechanism  to  assess  the  impact  of 
sensitive  information  and  ensure  that  it  gets  to  all  the 
parties  with  a  need  to  know.  Adding  to  this  problem  is 
the  lack  of  technical  communications  systems  to  enable 
the  secure  transmittal  of  classified  threat  information  to 
the  owners  and  operators  of  concern. 

T  he  above  issues  pose  a  significant  challenge  and  stand 
in  the  way  of  the  partnership  our  N  ation  needs  to  assure 
the  protection  of  its  critical  infrastructures  and  key 
assets.  U  nderlying  these  issues  is  an  inherent  lack  of 
trust  among  key  stakeholders  that  we  must  overcome. 

W  ithout  all  pieces  of  the  information  puzzle,  we  operate 
from  a  major  disadvantage  in  the  fight  against  terrorism. 

Information  Sharing  and  Indications 
and  W  arnings  I  nitiatives 

The  enactment  of  the  H  omeland  Security  Act  of  2002, 
the  Act,  represents  substantial  progress  in  removing  the 
legal  obstacles  that  stand  in  the  way  of  information 
sharing  between  the  public  and  private  sectors.  The  Act 
provides  that  critical  infrastructure  information 
voluntarily  submitted  to  D  H  S,  when  accompanied  by 
an  express  statement  of  the  expectation  that  it  will 
be  protected,  will  be  exempt  from  disclosure  under  the 
Freedom  of  I  n  formation  Act  and  state  "Sunshine"  laws. 
Further,  if  such  information  is  submitted  in  good  faith, 


it  may  not  be  directly  used  in  civil  litigation  without 
the  consent  of  the  person  submitting  it. 

The  Act  also  provides  for  the  establishment  of 
governmental  procedures  for  receiving,  handling,  and 
storing  voluntarily  submitted  critical  infrastructure 
information  and  for  protecting  the  confidentiality  of 
such  information.  It  also  provides  for  the  development 
of  mechanisms  that,  while  preserving  confidentiality, 
also  permit  the  sharing  of  such  information  within  the 
federal  government  and  with  state  and  local  govern¬ 
ments.  T  he  A  ct  authorizes  the  federal  government  to 
provide  advisories,  alerts,  and  warnings  to  relevant 
businesses,  targeted  sectors,  other  governmental  actors, 
and  the  general  public  regarding  potential  threats  to 
critical  infrastructure.  The  Act  also  stipulates  that  the 
federal  government  must  protect  the  source  of  any 
voluntarily  submitted  information  forming  the  basis  of 
a  warning  as  well  as  any  proprietary  or  other  informa¬ 
tion  that  is  not  properly  in  the  public  domain. 

Finally,  the  Act  enables  private- sector  actors  to  enter 
into  voluntary  agreements  to  promote  critical  infra¬ 
structure  security,  including  appropriate  forms  of 
information  sharing,  without  incurring  the  risk  of 
antitrust  liability.  U  nder  this  new  legal  regime,  D  FI  S 
will  be  able  to  give  proper  assurances  to  private- sector 
owners  and  operators  of  critical  infrastructure  that  the 
sensitive  or  proprietary  information  that  they  furnish 
will  be  protected.  These  assurances  will  encourage  the 
private  sector— which  is  uniquely  positioned  to  provide 
information  about  the  vulnerabilities  of  the  infrastruc¬ 
ture  it  owns  and  operates— to  share  that  vital 
information  with  the  government.  At  the  same  time, 
government  will  ensure  that  such  action  does  not 
diminish  competition  in  the  market  place. 

C  reating  a  more  effective  and  efficient  information¬ 
sharing  regime  to  enable  our  core  protective  missions 
will  require  further  government  leadership  and  intense 
collaboration  between  public-  and  private- sector 
stakeholders.  Specific  initiatives  include  efforts  to: 

D  efine  protection- related  information  sharing 
requirements  and  establish  effective,  efficient  information 
sharing  processes 

0  ne  of  the  first  steps  we  must  take  is  to  precisely 
define  information  sharing  requirements  as  they 
pertain  to  the  critical  infrastructure  and  key  asset 
protection  mission.  These  requirements  should  focus 
on  the  sharing  of  real-time  threat,  vulnerability,  and 
incident  data;  best  practices;  security  guidelines;  risk 
assessments;  and  operational  procedures.  D  FI  S,  in 
conjunction  with  DoJ,  DoS,  and  other  federal  lead 
departments  and  agencies,  will  lead  efforts  to 


26  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


establish  this  two-way  requirements  framework  in 
collaboration  with  other  key  stakeholders,  including 
international  partners.  0  nee  requirements  are 
determined,  processes  must  be  established  to  ensure 
that  the  appropriate  users  can  access  needed  infor¬ 
mation  in  a  timely  manner. 

I  mplement  the  statutory  authorities  and  powers  of  the 
H  omeland  Security  Act  of  2002  to  protect  security  and 
proprietary  information  regarded  as  sensitive  by  the 
private  sector 

To  facilitate  meaningful  information  exchange 
between  the  public  and  private  sectors,  we  will 
implement  the  provisions  of  the  Act  rapidly  to 
encourage  the  private  sector  to  share  sensitive 
security- related  information  and  incident  data. 
Accordingly,  within  the  framework  established  by 
the  Act,  D  H  S  will  work  with  D  oj,  C  ongress,  other 
federal  lead  departments  and  agencies,  and  state 
lawmakers  to: 

•  I  mplement  appropriate  protections  for  the 
private  sector  to  share  vulnerability  assessments, 
incident  reports,  and  other  security  data  with 
government;  and 

•  E  xplore  appropriate  mechanisms  to  share  and 
exchange  security- related  information  with  our 
international  partners. 

Promote  the  development  and  operation  of  critical  sector 
Information  Sharing  A  nalysisC  enters 

Sector- focused  I  SAC  s  provide  a  model  for  public- 
private  sector  information  sharing,  particularly  in  the 
area  of  indications  and  warnings.  N  umerous  critical 
infrastructure  sectors  use  this  structure  to  communi¬ 
cate  potential  risks,  threats,  vulnerabilities,  and 
incident  data  among  their  constituent  memberships. 

I  SAC  s  generally  have  mechanisms  in  place  that 
allow  them  to  share  many  categories  of  relevant, 
sensitive  information  in  a  timely  manner.  A  Ithough 
the  I  SAC  s  have  proven  to  be  a  successful  informa¬ 
tion  sharing  model  thus  far,  their  capabilities  could 
be  greatly  improved,  particularly  with  respect  to 
developing  advanced  analytical  capabilities.  D  H  S 
and  other  federal  lead  departments  and  agencies 
will  provide  increased  support  to  sector  efforts  to 
exchange  security- related  information  via  the 
ISACs.  Additionally,  D  H  S  will  work  with  industry 
to  establish  processes  and  mechanisms  to  help 
incorporate  state  and  local  government  participation 
into  the  I  SAC  process. 


I  mprove  processes  for  domesticthreat  data  collection, 
analysis,  and  dissemination  to  state  and  local  government 
and  private  industry 

0  ur  intelligence  community  has  longstanding 
processes  for  collection,  analysis,  and  dissemination 
of  information  on  threats  to  our  national  security 
interests.  We  must  establish  similar  collection  and 
assessment  processes  are  needed  to  integrate  infor¬ 
mation  from  all  sources  in  the  context  of  domestic 
critical  infrastructure  and  key  asset  protection. 

Additional  processes  must  be  put  in  place  to  ensure 
that  state  and  local  law  enforcement  and  infrastruc¬ 
ture  and  key  asset  owners  and  operators  have  full 
and  timely  access  to  needed  information,  including 
assessments  of  terrorist  organization  tactics,  tech¬ 
niques,  and  procedures;  assessments  of  terrorist 
capabilities  and  motivations;  lessons  learned  from 
terrorist  operations  in  other  countries;  and 
the  comprehensive  mapping  of  these  products  to 
sector  vulnerabilities. 

D  H  S,  in  collaboration  with  the  intelligence  commu¬ 
nity  and  the  DoJ,  will  develop  comprehensive  threat 
collection,  assessment,  and  dissemination  processes 
that  integrate  intelligence  and  law  enforcement 
capabilities  relevant  to  the  domestic  protection 
mission.  T  hey  will  also  develop  processes  to  ensure 
that  the  results  of  this  fusion  of  relevant  intelligence 
and  law  enforcement  data  are  disseminated  to  the 
appropriate  stakeholders  in  a  timely  manner.  This 
includes  exploring  ways  to  expedite  the  conduct  of 
necessary  background  checks  and  issuance  of  security 
clearances  to  those  with  a  need  to  know. 

Support  the  development  of  interoperable  secure 
communications  systems  for  state  and  local  governments 
and  designated  privatesector  entities 

D  H  S  will  enlist  the  assistance  of  experts  from 
N  I  ST,  the  D  epartment  of  D  efense  (D  oD ),  and 
other  appropriate  organizations  to  develop  technical 
systems  for  the  sharing  of  sensitive  information 
and  then  help  state  and  local  governments  acquire 
access  to  them. 

C  omplete  implementation  of  the  H  omeland  Security 
Advisory  System 

T  he  H  omeland  Security  A  dvisory  System  was 
implemented  in  early  2002.  D  H  S  will  continue  to 
work  with  other  federal  departments  and  agencies, 
state  and  local  governments,  and  the  private  sector 
to  interpret,  harmonize,  and  identify  appropriate 
actions  that  correspond  to  the  various  threat  levels 
included  in  this  system  as  they  relate  to  their  partic¬ 
ular  assets  and  operations. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  27 


PERSONNEL  SURETY,  BUILDING  HUMAN  CAPITAL, 
AND  AWARENESS 


D  omestic  security  starts  in  our  communities,  in  our 
own  institutions,  and  in  our  businesses.  Those  who 
have  access  to  and  operate  our  critical  infrastructures 
and  key  assets  are  crucial  to  our  national  protective 
scheme.  T  he  key  issues  impacting  personnel  surety, 
building  human  capital,  and  awareness  encompass 
four  main  areas: 

•  D  evel oping  safeguards  to  prevent  an  insider  or  a 
disaffected  or  co-opted  employee  from  conducting 
sabotage  activities  or  facilitating  terrorist  access  to  a 
critical  facility  or  system; 

•  Recruiting  and  training  more  skilled  operations 
and  security  personnel  to  protect  our  critical 
infrastructures  and  key  assets; 

•  Assuring  that  these  workers  are  secure  while  doing 
their  jobs;  and 

•  I  mplementing  communication  and  awareness 
programs  to  help  businesses  and  communities  take 
action  to  protect  their  respective  assets  and  manage 
risk  constructively. 


Personnel  Surety 

T  he  September  11  attacks  demonstrated  that  terrorist 
organizations  possess  the  capability  to  conduct  long¬ 
term  clandestine  operations,  with  individual  members 
blending  into  daily  life  in  the  U nited  States. The 
"insider  threat"  is  becoming  an  increasingly  serious 
concern  for  critical  infrastructure  and  key  asset 
protection  across  all  sectors.  A  n  "insider”  is  defined  as 
an  employee  or  anyone  else  who  has  routine  access  to 
critical  facilities  and  systems.  This  group  also  includes 
contractors,  temporary  help,  and  outsourcers.  I  nsiders, 
because  of  their  access  and  positions  of  trust,  can 
intentionally  or  unwittingly  become  terrorist  surrogates 
by  disclosing  information  relevant  to  critical  nodes, 
vulnerabilities,  operating  characteristics,  or  security 
measures.  T  hey  can  also  provide  terrorists  with  direct 
access  to  and  mobility  within  critical  facilities  and 
systems,  such  as  operations  centers  and  control  rooms. 

Building  H  uman  C  apital 

Related  to  personnel  surety  is  the  fundamental  need  to 
ensure  that  trustworthy,  reliable,  and  trained  personnel 
are  available  to  protect  critical  infrastructures  and  key 
assets  from  terrorist  attack.  Private  sector  owners  and 
operators  depend  on  skilled  employees  to  accomplish 
the  protection  mission.  Security  personnel  and  first 
responders,  in  particular,  require  adequate  training, 
equipment,  and  other  support  to  carry  out  their 
responsibilities  effectively  and  with  some  degree  of 
assurance  that  their  personal  security  will  not  be  in 
jeopardy  while  accomplishing  their  mission. 

Awareness 

A  state  of  sustained  preparedness  requires  widespread 
consciousness  among  members  of  the  public— 
especially  among  those  in  government  and  the  private 
sector  most  directly  affected—  of  the  scope  and  nature 
of  the  threat  we  face  and  the  precautions  we  must  take 
to  meet  the  threat.  T  he  federal  government,  working 
with  the  private  sector,  has  been  engaged  for  several 
years  in  a  systematic  program  to  develop  protection 
awareness  among  key  business  leaders  in  the  critical 
sectors.  This  effort,  which  has  increased  significantly 
since  September  11,  has  been  especially  productive. 
Additionally,  the  scope  of  the  attacks  themselves  and 
the  extensive  publicity  they  engendered  (e.g.,  congres¬ 
sional  hearings  and  media  coverage)  have  significantly 
raised  public  consciousness  of  the  terrorist  threat.  T  his 
level  of  awareness  must  be  sustained  over  the  long  term 
for  our  national  protective  effort  to  be  truly  successful. 


28  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


Personnel  Surety,  Building  H  uman  C apital, 
and  Awareness  C  hallenges 

T  i me- efficient,  thorough,  and  periodic  background 
screening  of  candidate  employees,  visitors,  permanent 
and  temporary  staff,  and  contractors  for  sensitive  posi¬ 
tions  is  an  important  tool  for  protecting  against  the 
"insider  threat.”  U  nfortunately,  in-depth  personnel 
screening  and  background  checks  are  often  beyond  the 
capabilities  of  private  sector  and  non-federal  govern¬ 
ment  entities.  Private  employers  also  lack  access  to 
personnel  reliability  data— often  in  the  possession  of  the 
federal  government— that  could  help  determine  whether 
employees,  contractors,  and  visitors  should  be  employed 
at  or  allowed  access  to  sensitive  facilities.  Part-time, 
temporary,  and  seasonal  workers  also  challenge  effective 
background  screening  processes  because  of  the  high 
level  of  employee  turnover.  Other  challenges  include 
concern  for  constitutional  freedoms,  costs  associated 
with  screening  processes,  and  a  lack  of  verifiable 
documentation  and  other  sources  of  information. 

Aside  from  personnel  surety,  shortages  of  skilled 
personnel  in  various  professions—  ranging  from  secu¬ 
rity  technicians  to  emergency  first  responders—  also 
impede  critical  infrastructure  and  key  asset  protection. 
Similarly,  although  private  security  officers  are  identi¬ 
fied  as  an  important  source  of  protection  for  critical 
facilities,  few  formal  standardized  qualifications, 
training,  or  certification  requirements  exist  for  these 
positions  across  the  critical  sectors.  G  iven  the  dynamic 
nature  of  the  terrorist  threat,  there  is  an  urgent  need 
for  ongoing  training  of  security  personnel  to  sustain 
skill  levels  and  to  remain  up-to-date  on  evolving 
terrorist  weapons  and  tactics. 

Protection  of  employees  from  the  terrorist  threat  or 
exposure  to  the  potential  aftereffects  of  an  attack  is  an 
important  concern  for  critical  infrastructure  and  key 
asset  owners  and  operators.  T  hey  are  also  potential 
disincentives  for  their  employees,  security  personnel, 
and  first  responders.  Future  attacks  could  result  in 
biological,  chemical,  or  radiological  contaminants  at  an 
incident  site  that,  without  proper  precautions,  could 
endanger  emergency  workers,  their  families  (by 
cross- contamination),  and  others  in  the  exposed  areas. 

D  espite  the  events  of  September  11,  awareness  of  the 
implications  of  terrorist  threats  to  critical  infrastruc¬ 
tures  among  members  of  industry  in  general  remains 
relatively  low.  As  time  passes  and  focus  on  the  events 
of  that  day  recedes,  the  awareness  and  interest  of  the 
general  public  also  recedes.  Asa  result,  security- related 
activities  could  lack  the  consistent  focus  required  to 
assure  protection,  thus  leaving  us  exposed  once  more. 


Personnel  Surety,  Building  H  uman  C  apital, 
and  Awareness  Initiatives 

T o  overcome  the  challenges  described  above, 
we  will: 

C  oordinate  the  development  of  national  standards  for 
personnel  surety 

D  H  S,  in  concert  with  D  oj,  will  convene  an  advisory 
task  force  to  perform  a  comprehensive  review  of 
critical  infrastructure  sector  personnel  surety 
programs.  T  he  task  force—  to  be  comprised  of 
federal  agencies  and  departments,  state  and  local 
governments,  and  private  sector  representatives— 
will  develop  advice  on  the  creation  of  national 
standards  and  capabilities  for  background  checks, 
screening,  criminal  investigations,  and  positive 
identification  of  key  personnel  employed  in  critical 
service  sectors. 

H  armonizing  personnel  surety  policies  and  programs 
among  critical  infrastructure  sectors  will  help  create 
uniform  standards  and  address  concerns  articulated 
by  businesses  regarding  the  adequacy  of  background 
checks  for  occupants  of  critical  job  categories.  I  n 
developing  national  standards  for  personnel  surety, 
however,  we  must  find  the  balance  that  enables  us 
to  mitigate  risk  and  defend  our  country  while 
preserving  individual  freedoms  and  liberties. 

D  eve/ op  a  certification  program  for  background¬ 
screening  companies 

T o  complement  private- sector  employer  efforts, 

D  H  S,  in  concert  with  D  oj,  will  develop  a  certifica¬ 
tion  program  for  background- screening  companies 
to  ensure  a  base-line  level  of  competence  and  reduce 
obstacles  to  timely  and  accurate  verification  of 
employee  backgrounds  and  investigative  histories. 

In  addition,  D  H  S  will  initiate  a  study  to  identify 
options  for  creating  or  enabling  access  to  databases 
to  accredit  candidates  for  critical  positions  and  other 
potential  hires,  contract  workers,  and  key  service 
supplier  personnel.  Federal  databases,  such  as  those 
operated  by  the  I  mmigration  and  N  aturalization 
Service  and  various  intelligence  and  law  enforce¬ 
ment  agencies,  could  be  used  to  seed  this  process. 

A  s  we  undertake  this  effort,  we  must  take  the 
precautions  necessary  to  protect  individual 
constitutional  freedoms. 

E  xplore  establishment  of  a  certification  regime  or  model 
security  training  program  for  private  security  officers 

T o  maximize  the  effectiveness  of  the  N  ation's  corps 
of  private  security  personnel,  D  FI  S  will  work  with 
law  enforcement  and  federal  security  officials  to 
initiate  a  dialogue  with  state  and  local  counterparts, 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  29 


private- sector  infrastructure  owners  and  operators, 
and  private  security  firms  concerning  the  creation  of 
a  training  and  certification  regime  for  private  secu¬ 
rity  officers.  0  ne  possible  model  is  the  program  for 
security  training  provided  by  the  federal  law 
enforcement  academies. 

I  dentify  requirements  and  develop  appropriate 

programs  to  protect  critical  personnel 

D  H  S  will  work  with  state  and  local  government  and 
industry  representatives  to  identify  requirements 
and  develop  appropriate  programs  to  protect  critical 
personnel  who  may  become  terrorist  targets  because 
of  their  roles  in  protection  activities. 

Security  and  first  responder  personnel  must  be 
assured  of  their  own  personal  safety  while  engaging 
in  their  protection  and  response  missions.  These 
personnel  may  need  to  be  equipped  with  the  protec¬ 
tive  devices  and  clothing  necessary  to  shield  them 
from  toxic  or  biological  contamination  and  impede 
the  transmission  of  potentially  dangerous  agents  to 
others.  I  n  this  regard,  personal  protective  equipment 
must  be  developed  with  the  needs  of  law  enforce¬ 
ment  and  other  first  responders  uppermost  in  mind 
across  the  critical  infrastructure  sectors.  Programs 
must  be  implemented  to  ensure  that  security 
personnel  and  first  responders  receive  protection 
training  and  education  necessary  for  them  to  carry 
out  their  responsibilities. 

Facilitate  the  sharing  of  public-  and  private'  sector 

protection  expertise 

D  H  S,  in  concert  with  other  federal  lead 
departments  and  agencies,  will  develop  a  program 
to  facilitate  the  sharing  of  protection  expertise 
between  the  public  and  private  sectors. 


T raining  and  exercises  that  test  protection  plans  and 
personnel  capabilities  are  critical  to  assessing 
required  improvements  in  preparedness  and  sharing 
best  practices.  Accordingly,  D  H  S  will  also  develop 
and  incorporate  realistic  hands-on  and  virtual  exer¬ 
cises  into  its  critical  infrastructure  and  key  asset 
protection  education  and  training  programs  with 
the  objective  of  exploring  common  protection  issues 
and  solutions.  W  ith  proper  design,  these  exercises 
can  serve  important  outreach,  training,  coordina¬ 
tion,  and  evaluation  purposes  across  the  public  and 
private  sectors. 

D  eve/op  and  implement  a  national  awareness  program 

for  critical  infrastructure  and  key  asset  protection 

D  H  S,  in  concert  with  other  key  stakeholders,  will 
identify  and  assess  the  requirements  for  a  compre¬ 
hensive,  national  awareness  program  that  will 
support  sustainability  of  preparedness  programs, 
security  investment,  and  protection  activities,  as 
well  as  the  public's  understanding  of  the  terrorist 
threat  environment. 

Building  awareness  means  creating  a  national 
appreciation  for  how  security  must  be  fundamentally 
incorporated  into  our  daily  lives  and  business  opera¬ 
tions.  0  ur  national  awareness  program  should  focus 
on  the  specific  needs  of  the  critical  infrastructure 
industries  to  support  informed  private- sector 
decisions  and  enable  the  planning  of  relevant  and 
effective  protection  strategies  and  resource  allocation. 

It  must  also  be  sufficiently  comprehensive  in  scope 
to  maintain  the  public’s  understanding  and  appreci¬ 
ation  of  the  threat  environment  as  it  evolves  and 
foster  confidence  in  the  strategies  and  approaches 
being  taken  to  address  it. 


30  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


TECHNOLOGY  AND 
RESEARCH  &  DEVELOPMENT 


T  he  terrorist  threat  challenges  us  to  marshal  our 
nation's  advantages  in  the  sciences  and  technology. 
Protecting  our  N  ation’s  critical  infrastructures  and  key 
assets  against  this  threat  will  require  a  systematic, 
national  effort  to  fully  harness  our  research  and  devel¬ 
opment  (R&D)  capabilities.  Doing  so  will  enable  us  to 
meet  many  of  our  immediate  needs  for  protective  stan¬ 
dards  and  solutions.  It  will  also  help  lay  the  long-term 
foundation  for  developing  the  advanced  tools  and  tech¬ 
nologies  that  will  enable  more  comprehensive  and 
cost-effective  protection  solutions  in  the  future,  partic¬ 
ularly  regarding  the  most  catastrophic  threats  we  may 
have  to  confront. 

0  rganizing  this  national  effort  will  require  persistence, 
careful  planning,  and  coordination.  0  ur  national 
research  enterprise  is  vast  and  complex.  Private  compa¬ 
nies,  universities,  research  institutions,  and  government 
laboratories  of  all  sizes  are  conducting  pure  and  applied 
research  to  develop  the  advanced  materials,  products, 
and  services  that  will  contribute  to  assuring  the  protec¬ 
tion  of  critical  infrastructures  and  key  assets. 

T o  best  realize  these  advances,  however,  we  must  be 
able  to  identify  needs—  standards,  tools,  and 
processes— that  span  multiple  sectors  as  a  critical  first 
step.  Accomplishing  this  will  enable  us  to  establish 
research  priorities  and  concentrate  efforts  and  assign 
responsibilities  in  these  areas  while  avoiding  unneces¬ 
sary  duplication  that  can  draw  valuable  capacity  away 
from  other  needed  research.  It  will  also  provide 
researchers,  engineers,  and  infrastructure  owners  and 
operators  with  a  minimum  threshold  of  capabilities  to 
guide  product  development  efforts  and  provide  end 
users  a  metric  to  gauge  the  sufficiency  of  the 
technological  solutions  they  adopt. 

Technology  and  Research 
&  Development  Challenges 

T  he  number  and  diversity  of  stakeholders  present 
impediments  to  coordinating  technological  R&  D 
activities  for  critical  infrastructure  and  key  asset  protec¬ 
tion.  0  rganizations  at  each  level  of  government  and 
across  the  critical  infrastructure  sectors  all  have 
individual  R&D  priorities  and  interests  intended  to 
identify  solutions  to  the  particular  problems  they 
consider  most  important.  0  ne  major  challenge  at  the 
outset  is  to  define  the  points  of  commonality  among 
these  disparate  needs  and  efforts  to  determine  where 
coordinated  R&D  activities  will  yield  value  across  the 
broadest  range  of  interests. 


At  the  national  level,  the  general  lack  of  focus  on  long¬ 
term  research,  development,  testing,  and  engineering 
for  critical  infrastructure  and  key  asset  protection  is  a 
significant  shortfall  in  our  current  domestic  protection 
posture.  A  need  exists  for  a  process  to  coordinate,  with 
broad  sector  input,  the  creation  and  adoption  of 
national  research  priorities,  and  support  to  cross- sector 
R&D  activities. 

In  addition,  our  domestic  protection  requirements 
create  a  demand  for  new  tools  to  contribute  to  security 
at  the  operational  level.  I  n  this  regard,  we  must  work  to 
improve  our  capability  to  conduct  a  wide  range  of  tests 
on  potential  contaminants  (e.g.,  biological,  chemical, 
and  radiological)  that  can  be  used  to  threaten  our  food 
and  agriculture,  water,  mass  transit,  and  other  sectors. 
Similarly,  we  must  expand  our  monitoring  and  surveil¬ 
lance  capabilities  to  improve  our  ability  to  detect  the 
presence  of  weapons  of  mass  destruction  and 
their  components. 

A  n  especially  great  need  exists  for  standards  to  support 
interoperable  communications.  T  he  current  lack  of 
capability  in  this  area  consistently  ranks  as  one  of  the 
most  critical  shortcomings  in  our  protection  and  emer¬ 
gency  response  posture  across  the  N  ation.  At  present, 
federal,  state,  and  local  law  enforcement  personnel  and 
fire,  medical,  and  emergency  management  personnel 
use  incompatible  communications  systems,  introducing 
difficulties  and  barriers  in  information  exchange  and 
security  operations.  This  lack  of  common  standards  in 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  31 


communications  equipment  can  seriously  impede  close 
collaboration  among  security  personnel,  first  respon¬ 
ders,  state  emergency  management  personnel,  and 
federal  officials  prior  to,  during,  and  in  the  aftermath 
of  a  terrorist  incident.  Responses  to  terrorist  incidents 
can  be  further  complicated  if  differences  in  communi¬ 
cations  connectivity  themselves  become  a  target  for 
terrorist  exploitation. 

The  lack  of  reliable  tools  to  authenticate  the  identities 
of  personnel  with  direct  access  to  our  most  critical 
facilities  and  systems  also  impedes  security  across 
sectors.  A  similar  situation  exists  with  respect  to  iden¬ 
tification  of  law  enforcement,  fire,  and  emergency 
response  personnel  working  in  protection  and  incident 
response  roles. 

Finally,  harmonizing  the  oftentimes  conflicting  need  to 
enhance  security  while  simultaneously  maintaining 
reasonably  open  channels  of  commerce  requires  both 
new  tools  and  processes  that  challenge  technology.  For 
example,  critical  dams,  particularly  those  on  navigable 
waterways,  present  difficult  security  challenges.  T  he 
locks  on  such  dams  must  remain  available  for  the  flow 
of  commerce,  yet  waterborne  threats  must  be  abated. 
Other  sectors  such  as  air  transportation,  rail  and 
maritime  shipping,  and  site  security  at  major  commer¬ 
cial  and  government  buildings,  national  landmarks,  and 
the  like  present  similar  needs  for  effective,  non-invasive 
monitoring  and  sensor  capabilities. 

Technology  and  Research 
&  D  evelopment  I  nitiatives 

T o  respond  to  these  challenges,  government  and 
industry  must  work  together  to  develop  standards  in 
security  technology  for  both  physical  and  information 
infrastructures.  Such  standards  would  enable  key 
stakeholders  to  collaborate  more  effectively  to  develop 
the  products  essential  to  enhancing  the  security  of 
infrastructures  and  managing  the  interdependencies 
among  them. 

Accordingly,  we  will: 

C  oordinate  public-  and  private-  sector  security  research 
and  development  activities 

D  FI  S  will  coordinate  with  other  appropriate  federal 
agencies  to  support  security  technology  research  and 
development,  including  specialized  pilot  programs 
and  projects. This  effort  will  include  exploration  of 
mechanisms  to  migrate  technologies  developed  by 
the  D  oD  and  other  government  agencies  to  the 
private  sector  for  use  in  infrastructure  protection. 
Activities  in  this  area  will  include  appropriate  collab¬ 
oration  with  our  international  partners  to  expand  our 


research  base  and  capitalize  on  technological 
solutions  being  developed  by  our  friends  and  allies. 

C  oordinate  interoperability  standards  to  ensure 

compatibility  of  communications  systems 

We  will  act  to  establish  and  disseminate  interoper¬ 
ability  standards  to  ensure  compatibility  of 
communications  systems  used  by  federal,  state, 
and  local  authorities. The  Federal  Communications 
Commission  (FCC),  will  lead  thiseffort,  working 
in  concert  with  D  FI  S,  other  federal  lead 
departments  and  agencies  such  as  D  0  C 's 
N  ational  T elecommunications  and  I  nformation 
Administration,  other  standard- setting  bodies  such 
as  NIST,  affected  user  groups,  and  equipment  manu¬ 
facturers.  E  stablishment  of  standards  will  enable 
secure  and  assured  interoperable  communications 
among  all  levels  of  homeland  security  entities. 
Standardized  communication  systems  will  enhance 
protection  and  incident  response,  as  well  as  promote 
efficient  planning  and  training  at  all  levels. 

E  xplore  methods  to  authenticate  and  verify 

personnel  identity 

We  must  provide  better  means  of  identifying  people 
in  order  to  increase  the  security  of  our  critical 
facilities,  systems,  and  functions.  We  must  create  a 
uniform  means  of  identifying  law  enforcement  and 
security  personnel  and  individuals  with  access  to 
critical  facilities  and  systems. 

T echnologies  to  be  examined  for  this  authentication 
scheme  include  biometric  identifiers,  magnetic 
strips,  microprocessor- enabled  "SM  ART " cards, 
and  other  systems.  Such  tools  would  enable  quick 
authentication  of  identities  in  the  protection  and 
emergency  response  domains.  T  he  enhanced  "scene 
control"  entailed  would  facilitate  investigations  at  the 
sites  of  terrorism  incidents,  and  create  an  investiga¬ 
tive  baseline  for  comparing  different  analytical  data. 

I  mprove  technical  surveillance,  monitoring  and 

detection  capabilities 

We  must  improve  our  technical  surveillance,  detec¬ 
tion  (including  non-invasive  inspection  methods), 
and  monitoring  systems  for  perimeter,  entry  area, 
and  key  node  vigilance.  We  must  also  develop 
more  robust  detection  systems  for  use  by  security 
personnel  across  our  critical  infrastructure  sectors. 

D  FI  S,  in  collaboration  with  other  public-  and 
private- sector  stakeholders,  will  develop  a  research 
agenda  to  explore  technical  solutions  to  surveillance 
and  detection  deficiencies  in  critical  sectors,  to 
include  capabilities  to  detect  chemical,  biological, 
and  radiological  (CBR)  residues. 


32  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


MODELING,  SIMULATION,  AND  ANALYSIS 


M  odeling,  simulation,  and  analysis  activities  help  to 
prioritize  critical  infrastructures  and  key  assets  protection 
activities  and  investments.  T  his  Strategy  has  discussed  the 
challenges  and  uncertainties  presented  by  critical  nodes 
and  single-points- of-failure  within  infrastructures,  as  well 
as  increasing  interdependencies  that  exist  among  the 
various  infrastructure  sectors  both  nationally  and  interna¬ 
tionally.  T  hese  interdependencies  and  key  nodes  are  often 
difficult  to  identify  and  resolve,  as  are  the  cascading  and 
cross- sector  effects  associated  with  their  disruption. 
Properly  employed,  modeling,  simulation,  and  analysis 
can  provide  valuable,  predictive  insights  into  potential 
consequences  that  could  result  from  these  dependencies 
and  interdependencies  in  various  threat  scenarios. 

M  odeling,  simulation,  and  analysis  can  also  facilitate 
protection  planning  and  decision  support  by  enabling 
the  mapping  of  complex  interrelationships  among  the 
elements  that  make  up  the  risk  environment.  For 
example,  modeling  traffic  patterns  through  a  particular 
junction,  such  as  rail  or  air  traffic  through  a  key 
railhead  or  air  terminal,  allows  analysis  of  the  various 
possible  outcomes  of  an  attack  on  that  node  at  various 
points  in  time.  Such  information  would  be  helpful  in 
drawing  attention  to  likely  cascading  consequences  that 
otherwise  might  have  gone  unconsidered. 

Using  models  and  simulations,  responsible  authorities 
can  evaluate  the  risks  associated  with  particular  vulner¬ 
abilities  more  accurately  and  subsequently  make  more 
informed  protection  decisions.  M  odeling  and  simula¬ 
tion  can  also  be  used  as  a  real-time  decision  support 
tool  to  help  mitigate  the  effects  of  an  attack  or  avert  a 
secondary  attack  altogether. 

Private- sector  infrastructure  and  asset  owners  and  opera¬ 
tors  possess  considerable  experience  in  preparing  for  and 
responding  to  a  wide  variety  of  naturally  occurring  events 


like  floods,  earthquakes,  and  hurricanes.  T  heir  expertise 
in  planning  and  response  stems  from  long  histories  of 
contending  with  the  challenges  associated  with  these 
naturally  occurring  phenomena.  In  contrast,  the  pervasive 
threat  of  terrorist  strikes  against  our  critical  infrastructures 
and  key  assets  is  relatively  new.  H  ence,  no  similar  long¬ 
term  data  exist  that  track  the  patterns  of  such  deliberate 
incidents;  nor  is  there  evidence  as  to  which  safeguards 
would  be  most  effective,  making  the  need  to  develop 
reliable,  predictive  surrogate  data  even  more  important. 

M  odeling,  Simulation,  and  Analysis C  hallenges 

H  istorically,  we  have  relied  on  modeling,  simulation,  and 
analysis  capabilities  to  enable  decision  support  and  plan¬ 
ning  activities  related  to  national  defense  and  intelligence 
missions.  We  must  now  find  ways  to  employ  them  to 
develop  creative  approaches  and  enable  complex  decision 
support,  risk  management,  and  resource  investment 
activities  to  combat  terrorism  at  home. 

M  odeling,  simulation,  and  analysis  would  provide 
significant  value  to  many  sectors  across  government 
and  the  economy.  Demands  for  such  studies  will  likely 
be  great;  and,  as  in  the  case  of  R&  D  planning,  we  will 
have  to  establish  priorities  among  the  projects  to  be 
undertaken,  giving  emphasis  to  those  studies  that  are 
likely  to  yield  common  benefits  and  address  the  most 
stressing  threats  and  vulnerabilities. 

Improving  our  modeling  and  simulation  resources 
must  also  include  an  effort  to  enhance  data  collection 
and  standardization.  Currently,  much  data  relevant 
to  national- level  protection  activities  may  not  exist, 
be  accessible,  or  reside  in  a  standard  format.  D  ata 
collection  processes,  systems,  and  standards  will  have 
to  be  created  and  adopted  to  provide  common 
representations  of  data  across  models  and  simulations. 

Furthermore,  enhancing  our  national  modeling, 
simulation,  and  analysis  capabilities  will  require  a  unified 
effort  across  the  public  and  private  sectors  to  yield  the 
results  needed  in  the  most  efficient  and  cost-effective 
manner  possible.  T  hrough  effective  partnering  across  the 
federal  interagency  community,  state  and  local  govern¬ 
ment,  national  laboratories,  academia,  and  commercial 
enterprises,  we  can  enlist  tremendous  talents  and 
resources  to  drive  this  capability  forward.  C  ross- sector 
collaboration  is  also  essential  to  establishing  standard 
methodologies  and  consistent  analytical  frameworks  for 
interpreting  research  results,  especially  when  modeling 
infrastructure  interdependencies. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  33 


M  ost  industry  officials  have  a  fairly  complete 
understanding  of  their  own  operations  and  associated 
vulnerabilities.  H  owever,  many  of  these  enterprises 
require  assistance  to  identify  their  dependencies  on 
other  sectors  and  the  degree  of  risk  to  which  they  are 
exposed  as  a  function  of  those  interdependencies.  T  he 
potential  impact  of  such  interdependencies  hit  home 
for  the  banking  and  financial  services  sector  on 
September  11,  when  the  collapse  of  the  World  T rade 
C  enter  towers  interrupted  telecommunications  services 
in  lower  M  anhattan.  The  disruption  brought  electronic 
financial  transactions  to  a  halt,  with  long-term 
economic  impacts  still  being  felt  more  than  a  year  later. 

I  n  most  cases,  modeling  and  simulation  capabilities  are  not 
well  integrated  into  existing  infrastructure  protection  plan¬ 
ning  activities.  Achieving  this  integration  will  be  critical 
to  the  task  of  translating  modeling  and  simulation  research 
data  into  effective  guides  for  sector- focused  protection 
planning,  decision  support,  and  resource  allocation. 

M  odeling,  Simulation,  and  A  nalysis  I  nitiatives 

M  odeling,  simulation,  and  analysis  initiatives  that  we 
will  pursue  across  the  critical  infrastructure  sectors 
include  efforts  to: 

Integrate  modeling,  simulation,  and  analysis  into  national 
infrastructure  and  asset  protection  planning  and  deasion 
support  activities 

D  H  S  will  establish  an  advisory  panel  consisting  of 
representatives  from  the  public  and  private  sectors, 
national  laboratories,  academia,  and  commercial 
research  organizations  to  explore  alternatives  to 
integrate  modeling  and  simulation  activities  into 
domestic  protection  planning. 

The  panel  will  be  charged  to  review  modeling, 
simulation,  and  analysis  and  advise  D  H  S  on  ways  to 
focus  on-going  and  planned  research  activities  on 
national  priorities.  E  arly  in  the  process,  emphasis  will 
be  given  to  developing  and  disseminating  standards 
and  methods  for  modeling  sector  interdependencies. 
Such  standards  will  be  based  on  a  clear  definition  of 
assets  or  services  deemed  to  be  critical  and  will  be 
tasked  for  development  through  nationally  coordi¬ 
nated  planning  activities  overseen  by  D  H  S. 

D  evefop  economic  models  of  near-  and  long-  term  effects  of 
terrorist  attacks 

The  economic  significance  of  terrorist  attacks  is  not 
always  clear,  with  short-term  effects  often  only 
partially  predictive  of  longer-term  realities.  M  odels 
of  the  temporal  and  cross- sector  scope  of  economic 
damage  caused  by  physical  infrastructure  attacks 
would  assist  policymakers  and  emergency  manage¬ 


ment  specialists  in  understanding  and  mitigating 
worst  case  effects. 

D  evefop  critical  noddchokepoint  and  interdependency 
analysiscapabilities 

Fundamental  to  the  core  objective  of  modeling 
interdependencies  and  mapping  the  consequences 
of  particular  terrorist  events,  we  will  also  undertake 
research  to  develop  metrics  for  gauging  the 
adequacy  of  infrastructure  subsystems  and  key  nodes 
compared  to  level  of  threat  and  effect.  T  his  includes 
comparing  the  robustness  of  different  infrastructures 
at  points  where  key  centers  or  critical  nodes  are 
in  close  proximity  to  one  another  and  can  have 
cascading  effects  if  attacked.  C  learly  identifying  and 
addressing  interdependencies  among  critical  infra¬ 
structures  in  both  a  national  and  international 
context  is  high  on  our  list  of  protection  priorities. 

M  odd  interdependencies  among  sectors  with  respect  to 
conflicts  between  sector  alert  and  warning  procedures 
and  actions 

M  odeling  alert  responses  and  possible  counter¬ 
productive  effects  of  alert  system  designs  will 
enhance  flexibility  and  minimize  duplication  of 
effort.  The  intent  of  raising  the  H  omeland  Security 
A  lert  status  is  to  trigger  actions  to  protect  infra¬ 
structures  and  make  it  more  difficult  for  terrorists  to 
act.  T  hese  actions,  however,  may  have  disruptive 
consequences  that  may  themselves  interact  in  ways 
that  could  create  additional  vulnerabilities. 

C  onduct  integrated  risk  modding  of  cyber  and  physical 
threats,  vulnerabilities  and  consequences 

Risk  assessments  help  to  identify  and  determine  ways 
to  manage  risk  to  best  allocate  resources.  T  hese  assess¬ 
ments  include  threat  analysis  to  provide  a  baseline 
and  frame  of  reference  for  risk  management  and 
investment  decisions.  This  analysis,  coupled  with 
vulnerability  assessments  to  determine  the  effectiveness 
of  security  systems  and  tools  to  provide  consequence 
analysis,  will  provide  information  on  critical  assets  and 
nodes.  Such  studies  would  comprise  models  of  security 
incidents  involving  various  types  of  both  cyber  and 
physical  attacks.  A  nalysis  will  focus  on  the  complex 
interactions  between  physical  and  cyber  systems  to 
determine  the  full  range  of  potential  consequences  and 
to  ensure  the  applicability  of  findings  across  infrastruc¬ 
tures  in  both  a  domestic  and  international  context. 

D  evefop  moddsto  improveinformation  integration 

The  integration  of  threat  and  vulnerability  informa¬ 
tion  between  sectors  needs  to  be  modeled,  as  does 
information  sharing  between  the  federal  govern¬ 
ment  and  critical  infrastructures,  to  identify  points 
of  inefficiency  and  information  loss. 


34  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


SECURING  CRITICAL 
INFRASTRUCTURES 


0  ur  society  and  modern  way  of  life  depend  on  a  complex 
system  of  critical  i nfrastructures.  T  he  N  ational  Strategy 
for  H  omel and  Security  has  identified  13  critical  sectors. 

A  s  we  learn  more  about  threats,  means  of  attack,  and  the 
various  criteria  that  make  targets  lucrative  for  terrorists, 
this  list  will  evolve.  The  critical  infrastructure  sectors 
consist  of  agriculture  and  food,  water,  public  health, 
emergency  services,  government,1  the  defense  industrial 
base,  information  and  telecommunications,2  energy, 
transportation,  banking  and  finance,  chemicals  and 
hazardous  materials,  and  postal  and  shipping.3  Common 
issues  of  concern  to  these  sectors  are  described  in  the 
C  ross-  S  ector  S  ecuri  ty  P  ri  ori  ti  es  ch  apter  of  th  i  s  strategy. 

For  each  critical  sector,  this  chapter  discusses: 

•  U  nique  characteristics  of  the  infrastructure  sector 
itself  and  the  industry  that  supports  it; 

•  C  urrent  efforts  that  are  underway  to  protect 
sector- specific  goods  and  service  delivery  and 
associated  critical  assets,  systems,  and  functions; 

•  U  nique  protection  challenges;  and 


•  Priority  protection  action  areas  for  the  sector  to 
address  in  a  collaborative  fashion. 

Consistent  with  the  principles  of  this  Strategy,  any 
initiatives  involving  significant  federal  resources  will 
be  prioritized  across  the  critical  sectors,  taking  into 
account  the  risks  and  consequences  of  potential  threats 
and  the  proper  sharing  of  protection  responsibilities 
among  the  various  stakeholders. 


1  The  primary  focus  of  this  Strategy  is  the  physical  protection 
of  critical  infrastructures  and  key  assets.  Each  lead  federal 
department  and  agency  has  developed  a  continuity  of  opera¬ 
tions  plan  (COOP)  to  ensure  the  continuity  of  government 
(COG)  for  its  sector.  As  these  plans  are  classified,  COG  will 
not  be  discussed  in  this  document. 

2  T  he  protective  strategy  for  information  technology  and 
network  assets  for  specific  sectors  is  discussed  in  detail  in  the 
National  Strategy  to  Secure  Cyberspace.  Accordingly,  the 
protection  of  the  I  nformation  T echnology  component  of  the 

I  nformation  and  T elecommunications  sector  is  not  discussed 
in  this  document. 

3  T  he  protection  of  National  M  onumentsand  I  cons  is 
addressed  in  Chapter  VI I, "Protecting  KeyAssets." 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  35 


AGRICULTURE  AND  FOOD 


From  farm  to  table,  our  N  ation’s  agriculture  and  food 
systems  are  among  the  most  efficient  and  productive  in 
the  world.  These  industries  are  a  source  of  essential 
commodities  in  the  U.S.,  and  they  account  for  close  to 
one- fifth  of  the  G  ross  D  omestic  Product.  A  significant 
percentage  of  that  figure  also  contributes  to  our  export 
economy,  as  the  U  .S.  exports  approximately  one  quarter 
of  its  farm  and  ranch  products. 

The  Agriculture  and  Food  Sectors  include: 

•  The  supply  chains  for  feed,  animals,  and  animal 
products; 

•  C  rop  production  and  the  supply  chains  of  seed, 
fertilizer,  and  other  necessary  related  materials;  and 

•  The  post- harvesting  components  of  the  food  supply 
chain,  from  processing,  production,  and  packaging 
through  storage  and  distribution  to  retail  sales, 
institutional  food  services,  and  restaurant  or 

home  consumption. 

C  hanges  in  the  ways  that  food  is  produced,  distributed, 
and  consumed  present  new  challenges  for  ensuring  its 
safety  and  security.  M  ore  of  our  food  is  grown  abroad, 
many  foods  are  transported  long  distances,  and  we  eat 
away  from  home  more  frequently.  Public  confidence 
in  the  safety  of  agricultural  and  food- processing  and 
packaging  systems  represents  a  key  part  of  sustaining 
the  economic  viability  of  these  sectors.  America’s 
reputation  as  a  reliable  supplier  of  safe,  high  quality 
foodstuffs  is  likewise  essential  to  maintaining  the 


confidence  of  foreign  customers  who  are  important  to 
the  national  economy  as  a  whole. 

The  U  nited  States  has  a  strong,  well  functioning 
food-safety  system  to  protect  the  public  against  unin¬ 
tentional  contamination  of  food  products.  Besides  the 
agriculture  and  food  industries’  measures  to  ensure 
food  safety,  the  overall  mechanism  includes  extensive 
analyses  of  critical  control  points  in  the  food  supply 
chain  and  federal,  state,  and  local  inspections  of  food 
processing  and  storage  facilities,  as  well  as  food  service 
establishments.  Sector  enterprises  are  currently  in  the 
process  of  assessing  physical  security  practices  and 
procedures  in  place  at  their  facilities,  particularly 
processing  plants. 

A griculture  and  Food  Sector  C  hallenges 

T  he  fundamental  need  for  food,  as  well  as  great  public 
sensitivity  to  food  safety  makes  assuring  the  security  of 
food  production  and  processing  a  high  priority. 

0  ur  food  and  agriculture  industries  have  been  devel¬ 
oped  over  several  decades  and  are  unique  with  respect 
to  their  structures  and  processes.  T  he  greatest  threats 
to  the  food  and  agricultural  systems  are  disease  and 
contamination,  in  which  case,  sector  decentralization 
represents  a  challenge  to  assuring  their  protection. 

G  overnment  and  industry  have  worked  together  in  the 
past  to  deal  with  isolated  instances  of  deliberate  food 
tamperi  ng.  T  he  effectiveness  of  the  food  safety  system 
with  regard  to  preventing,  detecting,  and  mitigating 


36  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


the  effects  of  unintentional  or  isolated  contaminations 
offers  a  foundation  to  build  upon  for  countering 
deliberate  acts  to  corrupt  the  food  supply. 

Because  of  the  food  system’s  many  points  of  entry 
detection  is  a  critical  tool  for  securing  the  agriculture 
and  food  sectors.  T  here  is  an  urgent  need  to  improve 
and  validate  analytical  methods  for  detecting  bioter¬ 
rorist  agents  in  food  products,  as  well  as  a  need  for 
enhanced  laboratory  capabilities  and  capacities.  The 
existing  system  of  federal,  state,  and  local  public  health 
and  agriculture  laboratories  was  established  to  detect 
the  presence  of  traditional  human  pathogens  that 
occasionally  and  unintentionally  contaminate  foods. 

A  Ithough  this  system  continues  to  serve  an  important 
role  in  safeguarding  public  health  from  these  tradi¬ 
tional  agents,  its  capabilities  must  be  enhanced  to 
enable  protection  from  a  wide  spectrum  of  nontradi- 
tional  agents.  T  his  enhanced  system  must  also  be 
capable  of  eliminating  the  occurrence  of  false  positives 
for  threat  agents  in  food  and  agricultural  products  in 
addition  to  inconsistencies  in  detecting  them  when 
they  are  present. 

Additionally,  we  must  expand  our  system  of  laborato¬ 
ries  to  accommodate  the  requirements  that  could  result 
from  a  bioterrorist  attack  on  the  food  supply.  We  must 
also  increase  the  number  of  qualified  personnel  (veteri¬ 
narians  and  lab  technicians)  and  laboratories  with  the 
ability  to  diagnose  and  treat  animal  disease  outbreaks 
and  crop  contamination.  M  oreover,  many  state  budgets 
for  such  inspection,  detection,  and  training  protocols 
will  need  to  be  revisited  to  provide  for  such  initiatives. 

M  oving  and  processing  crops  and  animals  require 
transporting  them  over  long  distances.  D  uring  trans¬ 
port,  these  resources  spend  time  in  storage  areas  and 
facilities  where  they  may  come  in  contact  with  other 
products.  Accordingly,  the  agriculture  and  food  sectors 
depend  on  transportation  system  owners  and  operators, 
particularly  regarding  trucks  and  containers,  to  meet 
the  safety  and  security  standards  necessary  to  protect 
food  products  in  transit.  We  must  improve  mechanisms 
designed  to  track  the  movement  of  animals  and 
commodities  in  transit  and  enable  officials  to  pinpoint 
where  an  outbreak  or  contamination  originates. 

Rapid  acquisition  and  use  of  threat  information  could 
help  to  prevent  an  attack  from  spreading  beyond 
individual  facilities  or  local  communities  to  become  a 
regional  or  national  problem.  Unfortunately,  serious 
institutional  barriers  and  disincentives  for  sharing  such 
information  exist  within  the  sectors  and  their  structures. 
For  instance,  there  are  significant,  direct  economic 


disincentives  associated  with  reporting  problems  or 
suspected  contamination  in  food  processing. 

M  eanwhile,  the  agriculture  and  food  markets  are  highly 
competitive,  and  many  parts  of  the  food  system  operate 
within  slim  profit  margins.  Asa  result,  some  companies 
may  be  more  likely  to  hold  onto  information  related  to 
incidents  involving  suspected  contamination  in  order  to 
prevent  the  potential  financial  consequences  of  what 
might  be  a  false  alarm. 

Protecting  the  public  from  an  outbreak  or  contamina¬ 
tion  incident  requires  timely  reporting  of  information 
for  prompt  decision-making  and  action.  In  the  current 
environment,  when  crops  or  animals  must  be  culled  or 
preventively  killed  to  deal  with  disease  or  contamina¬ 
tion,  the  fear  of  a  negative  public  response  and 
attendant  economic  implications  to  the  sector  may 
impede  the  needed  levels  of  response  in  the  agriculture 
and  food  sectors. 

D  el i berate  contaminations  by  terrorists  aim  to  harm 
people  or  animals  to  the  greatest  extent  possible. 
Another  principal  objective  is  to  create  panic  and 
inflict  economic  damage.  Because  of  the  influence  the 
media  has  on  how  the  public  responds  to  incidents, 
clear  and  accurate  communication  of  information 
to  news  outlets  is  essential.  0  fficial  spokespersons 
at  state,  regional,  and  national  levels  should  be 
pre- assigned.  Although  food  regulators  routinely 
communicate  with  industry  on  food-safety  issues, 
planning  for  public  communications  in  the  event  of  a 
deliberate  contamination  should  also  be  a  priority, 
as  should  defining  stakeholder  responsibilities  within 
those  plans. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  37 


Agriculture  and  Food  Sector  Initiatives 

Information  derived  from  assessment  of  sector 
food- safety  processes  and  procedures  can  provide  a 
foundation  for  developing  an  agriculture  and  food 
sector  critical  infrastructure  protection  system.  For 
example,  two  major  efforts  to  establish  procedures  for 
accidental  outbreaks  of  animal  disease  have  already 
been  completed.1  W  hile  plans  for  these  studies  were 
drafted  with  accidental  introductions  of  disease  or 
contamination  in  mind,  their  findings  and  recommen¬ 
dations  may  also  apply  to  intentional  acts.  A  nother 
example  of  ongoing  activities  in  this  area  is  the  imple¬ 
mentation  of  recommendations  from  the  1999  A  nimal 
and  Plan  H  ealth  Inspection  report, Safeguarding 
American  Plant  R  esources.  Further  study  and  collabora¬ 
tive  policy  development  are  required  to  determine 
whether  and  how  the  food  safety  system  could  be 
extended  to  deal  with  food  security  issues. 

Additional  agriculture  and  food  sector  protection 
initiatives  include  efforts  to: 

E  valuate  overall  sector  security  and  identify  and  address 
vulnerabilities 

D  FI  S  and  the  D  epartments  of  A  gri culture  (U  SD  A ) 
and  FI  ealth  and  FI  uman  Services  (FI  FI  S),  working 
in  collaboration  with  state  and  local  governments 
and  industry,  will  undertake  a  broad  risk  assessment 
of  the  agriculture  and  food  sectors  to  evaluate 
overall  security  and  identify  and  address  existing 
vulnerabilities. 

E  n  ha  nee  detection  and  testing  capabilities  across  the 
agricultural  and  food  networks 

D  FI  S,  USD  A,  and  FI  FI  S,  in  collaboration  with  state 
and  local  governments  and  industry,  will  work  to 
increase  detection  and  testing  capacity.  E  xploring 
mechanisms  to  improve  detection  capabilities, 
ranging  from  technology  development  to  increasing 
the  number  of  veterinary,  epidemiology,  and 
technical  specialists  at  the  state  level,  will  facilitate 


earlier  detection  and  response.  Enhancing 
trace- back  systems  and  increasing  detection 
capabilities  at  borders  and  ports  of  origin  will 
also  significantly  increase  protection.  Identifying, 
creating,  and  certifying  additional  laboratory 
capacity  across  the  country  would  likewise  increase 
the  speed  of  analysis  and  response. 

A  ssess  transportation -  related  security  risks 

D  FI  S,  U  SD  A ,  FI  FI  S,  and  the  D  epartment  of 
Transportation  (DoT)  will  work  with  representa¬ 
tives  from  the  agriculture  and  food  industries  to 
assess  security  risks  in  food  and  commodity  trans¬ 
port  and  develop  appropriate  solutions.  T  he  scope 
of  the  issues  requires  a  thorough  risk  assessment 
integrating  transportation  security  measures  into 
ongoing  and  newly  initiated  countermeasures 
undertaken  by  the  food  industry.  Additional  consid¬ 
erations  include  standardizing  the  methods  by 
which  the  agriculture  and  food  industries  report 
truck  hijackings  and  cargo  thefts,  and  then  dissemi¬ 
nating  these  reports  within  the  food  industry. 

Identify  potential  infrastructure  protection  incentives; 

identify  and  address  existing  disincentives 

D  FI  S  working  with  USD  A  and  FI  FI  S  will  explore 
options  for  developing  incentives  or  reducing 
disincentives  to  encourage  the  prompt  reporting 
of  problems. 

D  evelop  emergency  response  strategies 

D  FI  S,  USD  A,  and  FI  FI  S,  working  with  sector 
counterparts,  will  develop  a  strategy  to  coordinate 
risk  communications  and  other  emergency 
response  activities. 


1  T  hese  efforts  are  reported  in  T  he  Animal  H  ealth  Safeguarding 
Review:  Results  and  Recommendations,  October  2001,  by  the 
N  ational  Association  of  State  D epartments  of  Agriculture 
Research  Foundation,  and  TheLI .S.  N ational  Animal  H  ealth 
Emergency M  anagement System,  2001  Annual  Report. 


38  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


WATER 


The  N  ation's  water  sector  is  critical  from  both  a  public 
health  and  an  economic  standpoint.  T  he  water  sector 
consists  of  two  basic,  yet  vital,  components:  fresh  water 
supply  and  wastewater  collection  and  treatment.  Sector 
infrastructures  are  diverse,  complex,  and  distributed, 
ranging  from  systems  that  serve  a  few  customers  to 
those  that  serve  millions.  0  n  the  supply  side,  the 
primary  focus  of  critical  infrastructure  protection 
efforts  is  the  N  ation’s  170,000  public  water  systems. 
These  utilities  depend  on  reservoirs,  dams,  wells,  and 
aquifers,  as  well  as  treatment  facilities,  pumping 
stations,  aqueducts,  and  transmission  pipelines. The 
wastewater  industry’s  emphasis  is  on  the  19,500 
municipal  sanitary  sewer  systems,  including  an 
estimated  800,000  miles  of  sewer  lines.  Wastewater 
utilities  collect  and  treat  sewage  and  process  water 
from  domestic,  commercial,  and  industrial  sources. The 
wastewater  sector  also  includes  storm  water  systems 
that  collect  and  sometimes  treat  storm  water  runoff. 

T  he  water  sector  has  taken  great  strides  to  protect  its 
critical  facilities  and  systems.  For  instance,  government 
and  industry  have  developed  vulnerability  assessment 
methodologies  for  both  drinking  water  and  wastewater 
facilities  and  trained  thousands  of  utility  operators  to 
conduct  them.  I  n  response  to  the  PublicH  ealth  Security 
and  Bioterrorism  Preparedness  and  R  esponseAct  of  2002, 
the  E  nvironmental  Protection  Agency  (E  PA )  has  devel¬ 
oped  baseline  threat  information  to  use  in  conjunction 
with  vulnerability  assessments.  Furthermore,  to  defray 
some  of  the  cost  of  those  studies,  the  E  PA  has  provided 
assistance  to  drinking  water  systems  to  enable  them 
to  undertake  vulnerability  assessments  and  develop 
emergency  response  plans. 

To  improve  the  flow  of  information  among  water-sector 
organizations,  the  industry  has  begun  development  of 
its  sector- 1  SAC.  The  Water  I  SAC  will  provide  a  secure 
forum  for  gathering,  analyzing,  and  sharing  security- 
related  information.  Additionally,  several  federal 
agencies  are  working  together  to  improve  the  ware¬ 
housing  of  information  regarding  contamination 
threats,  such  as  the  release  of  biological,  chemical,  and 
radiological  substances  into  the  water  supply,  and  how 
to  respond  to  their  presence  in  drinking  water.  W  ith 
respect  to  identifying  new  technologies,  the  E  PA  has  an 
existing  program  that  develops  testing  protocols  and 
verifies  the  performance  of  innovative  technologies.  It 
has  also  initiated  a  new  program  to  verify  monitoring 
technologies  that  may  be  useful  in  detecting  or  avoiding 
biological  or  chemical  threats. 


W  ater  Sector  C  hallenges 

T  he  basic  human  need  for  water  and  the  concern  for 
maintaining  a  safe  water  supply  are  driving  factors 
for  water  infrastructure  protection.  Public  perception 
regarding  the  safety  of  the  N  ation’s  water  supply  is 
also  significant,  as  is  the  safety  of  people  who  reside 
or  work  near  water  facilities.  In  order  to  set  priorities 
among  the  wide  range  of  protective  measures  that 
should  be  taken,  the  water  sector  is  focusing  on  the 
types  of  infrastructure  attacks  that  could  result  in 
significant  human  casualties  and  property  damage  or 
widespread  economic  consequences.  In  general,  there 
are  four  areas  of  primary  concentration: 

•  P  hysical  damage  or  destruction  of  critical  assets, 
including  intentional  release  of  toxic  chemicals; 

•  Actual  or  threatened  contamination  of  the  water 
supply; 

•  Cyber  attack  on  information  management  systems 
or  other  electronic  systems;  and 

•  I  nterruption  of  services  from  another  infrastructure. 

T o  address  these  potential  threats,  the  sector  requires 
additional  focused  threat  information  in  order  to  direct 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  39 


investments  toward  enhancement  of  corresponding 
protective  measures.  T  he  water  sector  also  requires 
increased  monitoring  and  analytic  capabilities  to 
enhance  detection  of  biological,  chemical,  or  radiolog¬ 
ical  contaminants  that  could  be  intentionally  introduced 
into  the  water  supply.  Some  enterprises  are  already  in 
the  process  of  developing  advanced  monitoring  and 
sampling  technologies,  but  additional  resources  from 
the  water  sector  will  likely  be  needed.  E  nvironmental 
monitoring  techniques  and  technologies  and  appro¬ 
priate  laboratory  capabilities  require  enhancement  to 
provide  adequate  and  timely  analysis  of  water  samples 
to  ensure  early  warning  capabilities  and  assess  the 
effectiveness  of  clean-up  activities  should  an  incident 
occur.  Specific  innovations  needed  include  new  broad- 
spectrum  analytical  methods,  monitoring  strategies, 
sampling  protocols,  and  training. 

A  pproaches  to  emergency  response  and  the  handling  of 
security  incidents  at  water  facilities  vary  according  to 
state  and  local  policies  and  procedures.  W  ith  regard  to 
the  public  reaction  associated  with  contamination  or 
perceived  contamination,  it  is  essential  that  local,  state, 
and  federal  departments  and  agencies  coordinate  their 
protection  and  response  efforts.  M  aintaining  the  public's 
confidence  regarding  information  provided  and  the 
timeliness  of  the  message  is  critical.  Suspected  events 
concerning  water  systems  to  date  have  elicited  strong 
responses  that  involved  taking  systems  out  of  service 
until  their  integrity  could  be  verified,  announcing  the 
incident  to  the  public,  and  issuing  "boil  water"  orders. 

T  he  operations  of  the  water  sector  depend  extensively 
on  other  sectors.  T  he  heaviest  dependence  is  on  the 
energy  sector.  For  example,  running  pumps  to  move 
water  and  wastewater  and  operating  drinking  water 
and  wastewater  treatment  plants  require  large  amounts 
of  electricity.  To  a  lesser  extent,  the  water  sector  also 
depends  on  the  transportation  system  for  supplies  of 
water  treatment  chemicals,  on  natural  gas  pipelines  for 
the  energy  used  in  some  operational  activities,  and  on 
the  telecommunications  sector.  W  ater  and  wastewater 
systems  are  increasingly  automated  and  controlled  from 
remote  locations  for  efficiency. 


W ater  Sector  I  nitiatives 

Water  infrastructure  protection  initiatives  are  guided 
both  by  the  challenges  that  the  water  sector  faces  and 
by  recent  legislation.1  Additional  protection  initiatives 
include  efforts  to: 

I  dentifyhigh-  priority  vulnerabilitiesand  improve 
site  security 

E  PA ,  in  concert  with  D  H  S,  state  and  local 
governments,  and  other  water  sector  leaders,  will 
work  to  identify  processes  and  technologies  to  better 
secure  key  points  of  storage  and  distribution,  such  as 
dams,  pumping  stations,  chemical  storage  facilities, 
and  treatment  plants.  E  PA  and  D  H  S  will  also 
continue  to  provide  tools,  training,  technical  assis¬ 
tance,  and  limited  financial  assistance  for  research 
on  vulnerability- assessment  methodologies  and 
risk- management  strategies. 

I  mprove  sector  monitoring  and  analytic  capabili ties 

EPA  will  continue  to  work  with  sector  representa¬ 
tives  and  other  federal  agencies  to  improve 
information  on  contaminants  of  concern  and  to 
develop  appropriate  monitoring  and  analytical 
technologies  and  capabilities. 

I  mprove  sector-  wide  information  exdiangeand  coordinate 
contingency  planning 

D  H  S  and  E  PA  will  continue  to  work  with  the 
sector  coordinator  and  the  water  I  SAC  to  coordi¬ 
nate  timely  information  on  threats,  incidents,  and 
other  topics  of  special  interest  to  the  water  sector. 

D  H  S  and  E  PA  will  also  work  with  the  sector  and 
the  states  to  standardize  and  coordinate  emergency 
response  efforts  and  communications  protocols. 

Work  with  other  sectors  to  manage  unique  risks  resulting 
from  interdependencies 

D  H  S  and  E  PA  will  convene  cross- sector  working 
groups  to  develop  models  for  integrating  priorities 
and  emergency  response  plans  in  the  context  of 
interdependencies  between  the  water  sector  and 
other  critical  infrastructures. 


1  O  n  June  12,  2002,  President  Bush  signed  th ePublicH ealth 
Security  andB ioterrorism  P reparedness andR  esponseAct  of  2002 
(Bioterrorism  Act)  into  law.  T  he  Bioterrorism  Act  requires 
many  drinking  water  systems  to  conduct  vulnerability  assess¬ 
ments,  certify  and  submit  copies  of  their  assessments  to  E  PA , 
and  prepare  or  revise  their  emergency  response  plans. 


40  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


PUBLIC  HEALTH 


The  public  health  sector  is  vast  and  diverse.  It  consists 
of  state  and  local  health  departments,  hospitals, 
health  clinics,  mental  health  facilities,  nursing  homes, 
blood-supply  facilities,  laboratories,  mortuaries, 
and  pharmaceutical  stockpiles. 

H  ospitals,  clinics,  and  public  health  systems  play  a  crit¬ 
ical  role  in  mitigating  and  recovering  from  the  effects 
of  natural  disasters  or  deliberate  attacks  on  the  home¬ 
land.  Physical  damage  to  these  facilities  or  disruption 
of  their  operations  could  prevent  a  full,  effective 
response  and  exacerbate  the  outcome  of  an  emergency 
situation.  Even  if  a  hospital  or  public  health  facility 
were  not  the  direct  target  of  a  terrorist  strike,  it  could 
be  significantly  impacted  by  secondary  contamination 
involving  chemical,  radiological,  or  biological  agents. 

In  addition  to  established  medical  networks,  the  U.S. 
depends  on  several  highly  specialized  laboratory 
facilities  and  assets,  especially  those  related  to  disease 
control  and  vaccine  development  and  storage,  such  as 
the  H  H  S  C  enters  for  D  isease  C  ontrol  and  Prevention, 
the  N  ational  I  nstitutes  of  H  ealth,  and  the  N  ational 
Strategic  Stockpile. 

Public  H  ealth  Sector  C  hallenges 

Public  health  workers  are  accustomed  to  placing 
themselves  in  harm’s  way  during  an  emergency. 

T  hey  may  be  unlikely,  however,  to  view  themselves 
as  potential  targets  of  terrorist  acts. 

M  ost  hospitals  and  clinics  are  freely  accessible  facilities 
that  provide  the  public  with  an  array  of  vital  services. 

T  his  free  access,  however,  also  makes  it  difficult  to 
identify  potential  threats  or  prevent  malicious  entry 
into  these  facilities.  This  fact,  combined  with  a  lack  of 
means  and  standards  to  recognize  and  detect  poten¬ 
tially  contaminated  individuals,  can  have  an  important 
impact  on  facility  security  and  emergency  operations. 

Another  significant  challenge  is  the  variation  in 
structural  and  systems  design  within  our  hospitals  and 
clinics.  0  n  one  hand,  so-called  "immune  buildings" 
have  built-in  structural  design  elements  that  help 
prevent  contamination  and  the  spread  of  infectious 
agents  to  the  greatest  extent  possible.  Such  features 
include  controlled  airflow  systems,  isolation  rooms, 
and  special  surfaces  that  eliminate  infectious  agents 
on  contact.  At  the  other  extreme  are  buildings  with 
relatively  little  built-in  environmental  protection. 
Protection  of  this  category  of  facility  presents  the 
greatest  challenge. 


D  uring  an  epidemic,  infectious  individuals  who 
continue  to  operate  in  the  community  at  large  may 
pose  a  significant  public  health  risk.  T  he  sector  needs 
to  develop  comprehensive  protocols  governing  the 
isolation  of  infectious  individuals  during  a  crisis. 

Additional  public  health  sector  challenges  relate  to  the 
maintenance,  protection,  and  distribution  of  stockpiles 
of  critical  emergency  resources.  C  urrently,  other  than 
the  N  ational  Strategic  Stockpile,  there  are  limited 
resources  for  rotating  and  replenishing  supplies  of 
critical  materials  and  medicines.  Supply  chain  manage¬ 
ment  for  medical  materials  also  requires  greater 
attention  to  ensure  secure  and  efficient  functioning 
during  an  emergency.  Potential  solutions  to  these 
problems  are  impacted  by  complex  legal  and  tax  issues. 
C  urrently,  the  federal  government  has  only  limited 
regulatory  authority  to  request  information  from 
companies  concerning  their  available  inventory  of 
medical  supplies  and  their  capacity  to  produce  them. 
Since  pharmaceutical  companies  are  taxed  on  their 
product  inventories,  they  try  to  avoid  stockpiling 
finished  goods  and  meet  demand  through  "just-in- 
time"  manufacturing. 

Sector-specific  legal  and  regulatory  issues  also  tend  to 
impede  the  effective  protection  of  assets  and  services. 

T  he  E  mergency  M  edical  T  reatment  and  A  dive  L  abor  A  ct 
requires  hospitals  to  treat  patients  requiring  emergency 
care  regardless  of  their  insurance  status.  D  isaster 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  41 


situations  involving  mass  casualties  tax  the  resources  of 
critical  facilities  in  terms  of  manpower,  medical  supplies, 
and  space.  As  patients  are  stabilized,  it  is  often  necessary 
to  transfer  them  to  other  hospitals  to  free  up  critical 
resources  for  newly  arriving  casualties.  W  ith  respect  to 
disaster  victims  without  insurance,  however,  once  treat¬ 
ment  is  no  longer  an  emergency,  hospitals  are  not  bound 
to  treat  them.  Asa  result,  many  second- tier,  noncritical 
hospitals  will  not  or  cannot  accept  uninsured  patients, 
thereby  requiring  the  critical  hospital  by  default  to 
continue  nonemergency  treatment.  Additionally,  privacy 
rules  mandated  in  the  H  eatth  I  nsurenoe Portability  and 
AowntabilityAd  should  be  reviewed  to  determine 
whether  they  could  prevent  the  sharing  of  critical  data 
in  the  event  of  an  epidemic. 

Existing  security  challenges  have  focused  the  public 
health  sector  on  assessing  its  ability  to  deliver  critical 
services  during  a  crisis.  M  any  hospitals,  however,  are 
faced  with  operating  at  limited  profit  margins  and, 
therefore,  have  difficulty  making  appropriate 
security  investments. 

Finally,  specialized  medical  and  pharmaceutical 
laboratories  merit  special  attention—  particularly  those 
handling  highly  toxic  or  infectious  agents.  T  hese  facili¬ 
ties  are  mission -critical  with  respect  to  identifying 
hazardous  agents  should  an  attack  or  outbreak  occur. 
These  facilities  also  enable  the  containment,  neutral¬ 
ization,  and  disposal  of  such  hazardous  materials. 
Overcoming  the  protection  challenges  associated  with 
securing  these  specialized  assets  is  a  top  priority. 

Public  H  ealth  Sector  I  initiatives 

Public  health  sector  protection  initiatives  include 
efforts  to: 

D  es ignate  trusted  communicators 

H  H  S  will  work  with  state  and  local  public  health 
officials  to  identify,  appoint,  train,  and  prepare 
recognized  subject  matter  experts  to  speak  on  behalf 
of  the  public  health  sector  in  times  of  crisis. These 
appointees  would  act  as  important  envoys  of 
homeland  security  information  to  communicate 
consistent,  accurate  information,  as  well  as  to 
inform,  instruct,  and  reassure  the  American  public. 
Additionally,  FI  H  S  leaders  will  be  prepared  to  play 
substantial  roles  at  the  national  level  in  communi¬ 
cating  with  the  public  regarding  risks  associated  with 
bioterrorism  or  other  public  health  emergencies. 

R  eview  mission  critical  operations)  establish  protection 
priorities)  and  ensure  adequate  security  and  redundancy 
for  critical  laboratory  fadlitiesand  services 

FI  FI  S  will  work  with  hospitals  and  clinics  in  the 
public  health  sector  to  review  their  mission-critical 


systems  and  operations  and  help  them  create 
detailed  plans  to  focus  security  investments  and 
increase  their  protection.  In  partnership  with  state 
health  departments,  FI  FI  S  and  D  FI  S  will  identify 
and  prioritize  national- level  critical  hospitals  and 
medical  centers,  as  well  as  their  most  important 
component  facilities,  systems,  and  services. 

FI  FI  S  and  D  FI  S  will  work  with  the  health  care 
sector  to  ensure  that  key  laboratory  facilities  are 
protected  and  have  adequate  redundancy  with 
respect  to  critical  capabilities  and  data  systems. 

E  nhance  surveillance  and  communication  capabilities 

FI  FI  S  will  assist  public  health  sector  officials  to 
identify  requirements  for  robust  surveillance  systems 
and  coordinate  links  between  public  health  moni¬ 
toring  facilities  and  healthcare  delivery  systems. 

D  evefop  criteria  to  isolate  in  fecti ous  individuals  and 

establish  triage  protocols 

FI  FI  S  will  work  with  state  and  local  health  officials 
to  develop  isolation  and  quarantine  standards  to 
improve  the  protection  of  the  unaffected  population 
during  a  public  health  crisis.  FI  FI  S  will  also  work 
with  state  and  local  health  officials  during  conse¬ 
quence  management  planning  to  set  priorities  for 
the  deployment  of  vaccination  and  prophylaxis 
resources  in  of  the  event  of  a  terrorist  incident 
involving  biological  or  chemical  weapons. 

E  nhance  protection  of  emergency  stockpiles  of  medical 

supplies  and  domestic  and  international  pharmaceutical 

manufacturing  fadlities 

FI  FI  S  and  D  FI  S  will  work  with  the  health  care 
sector  to  enable  the  protection  of  stockpiles  of 
medical  supplies  and  other  critical  materials,  distri¬ 
bution  systems,  and  the  critical  systems  of  medical 
institutions,  including  basic  surveillance  capabilities 
necessary  for  tracking  the  spread  of  diseases  and 
toxic  agents.  Additionally,  FI  FI  S  will  identify 
providers  of  critical  resources  and  ensure  a  ready 
stockpile  of  vital  medicines  for  use  in  an  emergency. 

E  xplore  options  for  incentives  to  increase  security  spending 

In  partnership  with  state  health  departments,  FI  FI  S 
will  examine  legal  and  regulatory  impediments  that 
could  prevent  critical  health  facilities  from  providing 
critical  services  during  a  crisis.  FI  FI  S  will  also  explore 
possible  incentives  to  encourage  increased  invest¬ 
ment  in  the  physical  security  of  facilities  in  the 
public  health  sector.  T  he  current  federally  sponsored 
investment  program  to  improve  critical  hospital 
capabilities  within  local  communities  provides  an 
appropriate  point  of  departure  for  this  effort. 


42  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


EMERGENCY  SERVICES 


T  he  emergency  services  infrastructure  consists  of  fire, 
rescue,  emergency  medical  service  (EM  S),  and  law 
enforcement  organizations  that  are  employed  to  save 
lives  and  property  in  the  event  of  an  accident,  natural 
disaster,  or  terrorist  incident. 

E  mergency  Services  Sector  C  hallenges 

L  essons  learned  from  the  September  11  attacks  indicate 
that  the  most  pressing  problems  to  be  addressed  in  this 
sector  include:  inadequate  information  sharing  between 
different  organizations— particularly  between  law 
enforcement  and  other  first  responders;  telecommunica¬ 
tions  problems,  such  as  a  lack  of  redundant  systems; 
and  the  challenge  of  enhancing  force  protection 
through  such  measures  as  stronger  crime  scene  control 
and  enhanced  security  to  mitigate  secondary  attacks. 

Terrorists  pose  a  major  challenge  to  our  national 
emergency  response  network.  A  Ithough  the  existing 
infrastructure  is  sufficient  for  dealing  with  routine  acci¬ 
dents  and  regional  disasters,  the  September  11  attacks 
revealed  shortfalls  in  its  specific  capabilities  to  respond 
to  large- scale  terrorist  incidents  and  other  catastrophic 
disasters  requiring  extensive  cooperation  among  local, 
state,  and  federal  emergency  response  organizations. 

M  ost  pressing  among  these  shortfalls  has  been  the 
inability  of  multiple  first- responder  units,  such  as  police 
and  fire  departments,  to  coordinate  their  efforts—  even 
when  they  originate  from  the  same  jurisdiction. 

M  ajor  emergencies  require  cooperation  by  multiple 
public  agencies  and  local  communities.  Systems 
supporting  emergency  response  personnel,  however,  have 
been  specifically  developed  and  implemented  with 
respect  to  the  unique  needs  of  each  agency.  Such  specifi¬ 
cation  complicates  interoperability,  thereby  hindering  the 
ability  of  various  first  responder  organizations  to  commu¬ 
nicate  and  coordinate  resources  during  crisis  situations. 

Robust  communications  systems  are  essential  for 
personnel  safety  and  the  effective  employment  of 
human  resources  during  a  crisis  or  an  emergency. 
Failure  of  communications  systems  during  a  crisis 
impedes  the  speed  of  response  and  puts  the  lives  of 
responders  at  risk.  A  nother  important  issue  is  the 
extent  to  which  emergency  response  communications 
depend  on  key  physical  nodes,  such  as  a  central 
dispatcher,  firehouse,  or  911-call  center. 

U  nlike  most  critical  infrastructures,  which  are  closely 
tied  to  physical  facilities,  the  emergency  services  sector 
consists  of  highly  mobile  teams  of  specialized 


personnel  and  equipment.  A  nother  challenge  for  the 
emergency  services  sector,  therefore,  is  assuring  the 
protection  of  first  responders  and  critical  resources 
during  emergency  response  operations.  Future  terrorist 
incidents  could  present  unseen  hazards  at  incident 
sites,  including  the  risk  of  exposure  to  C  BR  agents. 

M  oreover,  past  experience  indicates  that  emergency 
services  response  infrastructure  and  personnel  can  also 
be  the  targets  of  deliberate  direct  or  secondary  attacks, 
a  bad  scenario  that  could  be  made  worse  by  communi¬ 
cation  difficulties  and  responding  units  that  are 
ill-prepared  for  such  a  likelihood. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  43 


Preparedness  exercises  serve  to  provide  experience  and 
feedback  on  preparation  for  response  and  emergency 
management  activities.  Various  state  and  local  govern¬ 
ments  and  federal  agencies  have  hosted  local  or 
regional  exercises.  T  he  approaches  used  vary  widely— 
a  fact  that  could  impede  the  effectiveness  of  multi- 
jurisdictional  response  efforts. 

Faced  with  the  threat  of  a  major  terrorist  attack, 
no  single  jurisdiction  has  the  ability  to  maintain  or 
assemble  all  of  the  resources  necessary  to  provide  an 
effective  response.  M  utual  aid  agreements  facilitate  the 
flow  of  public  safety  personnel,  equipment,  and  other 
vital  resources  across  jurisdictional  boundaries  to 
enable  local  communities  to  help  each  other  during 
emergencies  and  disasters. 

E  mergency  Services  Sector  I  nitiatives 

E  mergency  services  sector  protection  and  response 
initiatives  include  efforts  to: 

A  dopt  interoperable  communications  systems 

D  FI  S  and  D  oj  will  work  with  state  and  local 
governments  and  other  appropriate  entities  to  study 
and  resolve  important  communications  interoper¬ 
ability  issues.  T  his  problem  is  already  widely 
recognized  and  accepted  as  a  valid  concern  at  the 
state  and  local  government  level.  T  he  common, 
overriding  need  to  assure  effective  communications 
during  an  emergency  can  be  used  as  a  catalyst  to 
drive  individual  agencies  toward  a  solution. 

D  a/efop  redundant  communications  networks 

D  FI  S  will  work  with  state  and  local  officials  to 
develop  redundant  emergency  response  networks  to 


improve  communications  availability  and  reliability, 
especially  during  a  major  disruption. 

I  mplement  measures  to  protect  our  national  emergency 
response  infrastructure 

D  H  S  will  inventory  and  analyze  the  vulnerability  of 
our  national  emergency  response  infrastructure, 
including  critical  personnel,  facilities,  systems,  and 
functions.  D  FI  S  will  work  with  states,  localities,  and 
other  entities  to  develop  plans  to  assure  the  safety 
of  personnel  during  response  efforts,  as  well  as  the 
protection  of  our  emergency  response  critical 
infrastructure. 

C  oordinatenational  preparedness  exerdses 

D  FI  S  will  work  with  state  and  local  governments  to 
develop  a  coordinated  national  emergency  response 
exercise  program.  Coordinated  preparedness 
exercises  would  promote  consistency  in  protection 
planning  and  response  protocols  and  capabilities  at 
the  regional  and  national  levels,  as  well  as  provide  a 
forum  for  sharing  lessons  learned  and  best  practices. 

E  nhanceand  strengthen  mutual  aid  agreements  among 
local  jurisdictions 

D  FIS  will  work  with  officials  from  local  communi¬ 
ties  to  strengthen  existing  mutual  aid  agreements 
and  develop  new  ones  in  regions  across  the  U  .S. 
where  needed.  Furthermore,  it  will  promote  discus¬ 
sion  regarding  the  adoption  of  common  standards 
and  terminology  for  equipment  and  training. 


44  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


DEFENSE  INDUSTRIAL  BASE 


0  ur  nation’s  defense  and  military  strength  rely 
primarily  on  the  D  oD  and  the  private  sector  defense 
industry  that  supports  it.  W  ithout  the  important 
contributions  of  the  private  sector,  D  oD  cannot  effec¬ 
tively  execute  its  core  defense  missions,  including 
mobilization  and  deployment  of  our  nation’s  military 
forces  abroad.  C  onversely,  private  industry  and  the 
public  at  large  rely  on  the  federal  government  to 
provide  for  the  common  defense  of  our  N  ation  and 
protect  our  interests  both  domestically  and  abroad. 

Success  in  the  war  on  terrorism  depends  on  the  ability 
of  the  U  nited  States  military  to  mount  swift,  calculated 
offensive  and  defensive  operations.  E  nsuring  that  our 
military  is  well  trained  and  properly  equipped  is  critical 
to  maintaining  that  capability.  Private  industry  manu¬ 
factures  and  provides  the  majority  of  the  equipment, 
materials,  services,  and  weaponry  used  by  our  armed 
forces.  For  several  decades,  D  oD  has  worked  to 
identify  its  own  critical  assets  and  systems.  It  has 
also  begun  to  address  its  dependency  on  the  defense 
industrial  base,  and  is  now  taking  the  concerns  of 
private  industry  into  consideration  in  its  critical 
infrastructure  protection  assessment  efforts. 


suppliers  in  the  world  capable  of  satisfying  these 
unique  requirements.  M  any  of  these  sources  have 
single  manufacturing  and  distribution  points  that 
warrant  additional  security  review  and  assessment. 


M  arket  competition,  consolidations,  globalization,  and 
attrition  have  reduced  or  eliminated  redundant  sources 
of  products  and  services  and  therefore  increased  risk  for 
DoD .  0  utsourcing  and  complex  domestic  and  foreign 
corporate  mergers  and  acquisitions  have  made  it  even 
more  difficult  for  D  oD  to  be  assured  that  its  prime 
contractors’  second-,  third-,  and  fourth-tier  subcontrac¬ 
tors  understand  its  security  requirements  and  are 
prepared  to  support  them  in  a  national  emergency. 

D  efense  I  ndustrial  B  ase  C  hallenges 

0  ver  the  past  20  years,  D  oD 's  dependency  on  the 
private  sector  has  greatly  increased.  0  utsourcing  has 
caused  the  department  to  rely  increasingly  on  contrac¬ 
tors  to  perform  many  of  the  tasks  that  were  once  under 
the  exclusive  purview  and  control  of  the  military.  E  ven 
the  utilities  that  service  many  of  the  nation’s  important 
military  installations  are  being  privatized.  Because  of 
market  competition  and  attrition,  DoD  now  relies 
more  and  more  on  a  single  or  very  limited  number  of 
private- sector  suppliers  to  fulfill  some  of  its  most 
essential  needs.  DoD,  unlike  other  federal  government 
agencies,  requires  strict  adherence  to  military  product 
specification  and  unique  requirements  for  services. 
Select  private-industry  vendors  may  be  the  only 


A  related  problem  involves  the  current  process 
through  which  D  oD  contracts  with  the  private  sector 
to  provide  critical  services  and  supplies.  M  ost  often 
the  procurement  process  is  based  on  cost  and  effi¬ 
ciency.  Such  an  approach  may  not  always  take  into 
account  the  vendor's  critical  infrastructure  protection 
practices  (e.g.,  workforce  hiring,  supplier  base)  and  its 
ability  to  supply  products  and  services  and  provide 
surge  response  during  an  emergency  or  exigent 
circumstances. 

Finally,  there  are  also  growing  concerns  within  the 
private  sector  regarding  the  potential  for  additional 
costs  and  risks  resulting  from  federal  mandates  that 
require  private  industry  to  implement  enhanced 
infrastructure  protection  measures. 

D  efense  I  ndustrial  Base  I  nitiatives 

T  he  infrastructures  of  the  private  defense  industry  and 
D  oD  are  already  integrated  on  many  levels.  D  oD ,  in 
concert  with  D  H  S,  will  continue  working  with  the 
private  sector  to  identify  critical  installations  and 
infrastructures,  and,  subsequently,  to  delineate  specific 
protection  requirements.  Furthermore,  DoD  and  D FH  S 
will  collaborate  with  key  defense  industrial  base 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  45 


organizations  to  integrate  and  build  upon  their 
individual  existing  protection  plans. 

Additional  defense  industrial  base  protection  initiatives 
include  efforts  to: 

Build  critical  infrastructure  protection  requirements  into 
contract  processes  and  procedures 

D  oD  will  collaborate  with  the  defense  industry  to 
review  contract  processes  and  procedures  to  deter¬ 
mine  how  to  include  provisions  that  address  critical 
infrastructure  protection  needs.  Contracts  will 
specifically  address  national  emergency  situation 
requirements,  such  as  contractor  response  times, 
supply  and  labor  availability,  and  direct  logistic 
support.  W  hen  appropriate,  contracts  will  also 
include  language  regarding  program  manager 
accountability  for  the  protection  of  supporting 
infrastructures.  Sensitive  contractual  documents 


will  receive  greater  scrutiny  and  revision  prior  to 
public  posting.  Additionally,  D  oD  will  give  specific 
scrutiny  to  its  potential  dependency  on  foreign 
commercial  operators  and  suppliers. 

I  ncorporate  security  concerns  into  production  and 
distribution  processes  and  procedures 

DoD  and  industry  will  explore  ways  to  eliminate 
key  production  and  distribution  bottlenecks. 

D  evelop  an  effective  means  of  sharing  security- related 
information  between  defense  organizations  and 
private- sector  service  providers 

D  oD  will  work  with  D  H  S  and  the  intelligence 
and  law  enforcement  communities  to  establish  the 
n  ecessary  po  I  i  ci  es  an  d  m  ech  an  i  sm  s  to  f aci  I  i  tate  a 
productive  exchange  of  security- related  information 
with  the  defense  industry. 


46  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


TELECOMMUNICATIONS 


T  he  composition  of  the  telecommunications  sector 
evolves  continuously  due  to  technology  advances, 
business  and  competitive  pressures,  and  changes  in  the 
regulatory  environment.  D  espite  its  dynamic  nature, 
the  sector  has  consistently  provided  robust  and  reliable 
communications  and  processes  to  meet  the  needs  of 
businesses  and  governments.  I  n  the  new  threat 
environment,  the  sector  faces  significant  challenges  to 
protect  its  vast  and  dispersed  critical  assets,  both  cyber 
and  physical.  Because  the  government  and  critical- 
infrastructure  industries  rely  heavily  on  the  public 
telecommunications  infrastructure  for  vital  communi¬ 
cations  services,  the  sector's  protection  initiatives  are 
particularly  important. 

T  he  telecommunications  sector  provides  voice  and  data 
service  to  public  and  private  users  through  a  complex 
and  diverse  public- network  infrastructure  encom¬ 
passing  the  Public  Switched  T elecommunications 
N  etwork  (PST  N  ),  the  I  nternet,  and  private  enterprise 
networks.  The  PSTN  provides  switched  circuits  for 
telephone,  data,  and  leased  point-to-point  services. 

It  consists  of  physical  facilities,  including  over  20,000 
switches,  access  tandems,  and  other  equipment.  T  hese 
components  are  connected  by  nearly  two  billion  miles 
of  fiber  and  copper  cable. T he  physical  PSTN  remains 
the  backbone  of  the  infrastructure,  with  cellular, 
microwave,  and  satellite  technologies  providing 
extended  gateways  to  the  wireline  network  for  mobile 
users.  Supporting  the  underlying  PST  N  are 
Operations,  Administration,  M  aintenance,  and 
Provisioning  systems,  which  provide  the  vital  manage¬ 
ment  and  administrative  functions,  such  as  billing, 
accounting,  configuration,  and  security  management. 

Advances  in  data  network  technology  and  the 
increasing  demand  for  data  services  have  spawned  the 
rapid  proliferation  of  the  Internet  infrastructure. 

T  he  I  nternet  consists  of  a  global  network  of  packet- 
switched  networks  that  use  a  common  suite  of 
protocols.  Internet  Service  Providers  (ISPs)  provide 
end-  users  with  access  to  the  I  nternet.  L  arger  I  SPs  use 
N  etwork  0  peration  C  enters  (N  0  C  s)  to  manage  their 
high  capacity  networks,  linking  them  through  Internet 
peering  points  or  network  access  points.  Smaller  ISPs 
usually  lease  their  long-haul  transmission  capacity  from 
the  larger  I  SPs  and  provide  regional  and  local  I  nternet 
access  to  end-users  via  the  PST  N  .  I  nternet  access 
providers  interconnect  with  the  PST  N  through  points 


of  presence,  typically  a  switch  or  a  router,  located  at 
carrier  central  offices.  I nternational  PSTN  and 
I  nternet  traffic  travels  via  underwater  cables  that  reach 
the  United  States  at  various  cable  landing  points. 

In  addition  to  the  P ST  N  and  the  I  nternet,  enterprise 
networks  are  an  important  component  of  the  telecom¬ 
munications  infrastructure.  E  nterprise  networks  are 
dedicated  networks  supporting  the  voice  and  data 
needs  and  operations  of  large  enterprises.  T  hese 
networks  comprise  a  combination  of  leased  lines  or 
services  from  the  PST  N  or  I  nternet  providers. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  47 


TheTdecommunicationsAd  of  1996  opened  local  PSTN 
service  to  competition.  It  required  incumbent  carriers 
to  allow  their  competitors  to  have  open  access  to  their 
networks.  Asa  result,  carriers  began  to  concentrate 
their  assets  in  collocation  facilities  and  other  buildings 
known  as  telecom  hotels,  collocation  sites,  or  peering 
points  instead  of  laying  down  new  cable.  ISPs  also 
gravitated  to  these  facilities  to  reduce  the  costs  of 
exchanging  traffic  with  other  ISPs.  0  pen  competition, 
therefore,  has  caused  the  operation  of  the  P ST  N  and 
the  Internet  (including  switching,  transport,  signaling, 
routing,  control,  security,  and  management)  to  become 
increasingly  interconnected,  software  driven,  and 
remotely  managed,  while  the  industry’s  physical  assets 
are  increasingly  concentrated  in  shared  facilities. 

T  he  telecommunications  infrastructure  is  undergoing  a 
significant  transformation  that  involves  the  conver¬ 
gence  of  traditional  circuit-switched  networks  with 
broadband  packet-based  IP  networks,  including  the 
Internet.  Eventually,  the  packet  networks  will  subsume 
the  circuit- switched  networks,  leading  to  the  establish¬ 
ment  of  a  public,  broadband,  diverse,  and  scaleable 
packet- based  network  known  as  the  N  ext  G  eneration 
N  etwork  (NGN).  Additionally,  the  evolution  of  the 
telecommunications  infrastructure  has  included  steady 
growth  in  mobile  wireless  services  and  applications. 

W  ireless  telecommunications  providers  transmit 
messages  using  an  infrastructure  of  base  stations  and 
radio- cell  towers  located  throughout  the  wireless 
provider’s  service  area.  W  ireless  services  consist  of 
digital  mobile  phones  and  emerging  data  services, 
including  I  nternet  communications,  wireless  local-area 
networks,  and  advanced  telephony  services. 

C  onvergence,  the  growth  of  the  N  G  N  ,  and  emergence 
of  new  wireless  capabilities  continue  to  introduce  new 
physical  components  to  the  telecommunications 
infrastructure.  G  overnment  and  industry  consistently 
work  together  to  develop  strategies  to  ensure  that  the 
evolving  infrastructure  remains  reliable,  robust,  and 
secure.  Public- private  partnerships  and  organizations 
currently  addressing  telecommunications  security 
include  the  President’s  N  ational  Security 
T  el  ecommunications  Advisory  C  ommittee  and 
Critical  Infrastructure  Protection  Board  (PC  I PB),  the 
G  overnment  N  etwork  Security  I  nformation  E  xchanges, 
theTelecommunications  I  SAC ,  and  the  N  etwork 
Reliability  and  Interoperability  Council  oftheFCC. 
Recommendations  by  these  bodies  and  collaboration 
among  industry  and  government  will  shape  the  security 
and  reliability  of  the  evolving  infrastructure. 


T  elecommunications  Sector  C  hallenges 

E  very  day  the  sector  must  contend  with  traditional 
natural  and  human-based  threats  to  its  physical  infra¬ 
structure,  such  as  weather  events,  unintentional  cable 
cuts,  and  the  insider  threat  (e.g.,  physical  and  cyber 
sabotage).  T  he  September  11  attacks  revealed  the 
threat  terrorism  poses  to  the  telecommunications 
sector's  physical  infrastructure.  W  hile  it  was  not  a 
direct  target  of  the  attacks,  the  telecommunications 
sector  suffered  significant  collateral  damage.  In  the 
future,  certain  concentrations  of  key  sector  assets 
themselves  could  become  attractive  direct  targets  for 
terrorists,  particularly  with  the  increased  use  of  colloca¬ 
tion  facilities.  The  telecommunications  infrastructure 
withstood  the  September  11  attacks  in  overall  terms 
and  demonstrated  remarkable  resiliency  because 
damage  to  telecommunications  assets  at  the  attack 
sites  was  offset  by  diverse,  redundant,  and  multifaceted 
communications  capabilities. 

Priorities  for  telecommunications  carriers  are  service 
reliability,  cost  balancing,  security,  and  effective  risk 
management  postures.  T  he  government  places  high 
priority  on  the  consistent  application  of  security  across 
the  infrastructure.  Although  private-  and  public-sector 


48  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


stakeholders  share  similar  objectives,  they  have 
different  perspectives  on  what  constitutes  acceptable 
risk  and  how  to  achieve  security  and  reliability. 

T  herefore,  an  agreement  on  a  sustainable  security 
threshold  and  corresponding  security  requirements 
remains  elusive. 

Because  of  growing  interdependencies  among  the 
various  critical  infrastructures,  a  direct  or  indirect  attack 
on  any  of  them  could  result  in  cascading  effects  across 
the  others.  Such  interdependencies  increase  the  need  to 
identify  critical  assets  and  secure  them  against  both 
physical  and  cyber  threats.  C  ritical  infrastructures  rely 
upon  a  secure  and  robust  telecommunications  infra¬ 
structure.  Redundancy  within  the  infrastructure  is 
critical  to  ensure  that  single  points  of  failure  in  one 
infrastructure  will  not  adversely  impact  others.  It  is  vital 
that  government  and  industry  work  together  to  charac¬ 
terize  the  state  of  diversity  in  the  telecommunications 
architecture.  T  hey  must  also  collaborate  to  understand 
the  topography  of  the  physical  components  of  the 
architecture  to  establish  a  foundation  for  defining  a 
strategy  to  ensure  physical  and  logical  diversity. 

D  espite  significant  challenges,  the  telecommunications 
marketplace  remains  competitive,  and  customer 
demand  for  services  is  steady,  if  not  increasing.  A  n 
economic  upturn  within  the  industry  could  rapidly 
accelerate  service  demands.  T  he  interplay  of  market 
forces  and  FCC  oversight  will  ensure  the  continuance 
of  service  delivery  to  sustain  critical  telecommunica¬ 
tions  functions.  N  evertheless,  recent  economic  distress 
has  forced  companies  to  spend  their  existing  resources 
on  basic  network  operations  rather  than  re-capitalizing, 
securing,  and  enhancing  the  infrastructure,  which  could 
amplify  the  financial  impact  of  necessary  infrastructure 
protection  investments. 

T elecommunications  Sector  I  nitiatives 

G  iven  the  reality  of  the  physical  and  cyber  threats 
to  the  telecommunications  sector,  government  and 
industry  must  continue  to  work  together  to  understand 
vulnerabilities,  develop  countermeasures,  establish 
policies  and  procedures,  and  raise  awareness  necessary 
to  mitigate  risks.  T  he  telecommunications  sector  has 
a  long,  successful  history  of  collaboration  with 
government  to  address  concerns  over  the  reliability 
and  security  of  the  telecommunications  infrastructure. 


T  he  sector  has  recently  undertaken  a  variety  of  new 
initiatives  to  further  ensure  both  reliability  and  quick 
recovery  and  reconstitution.  W  ithin  this  environment 
of  increasing  emphasis  on  protection  issues,  public- 
private  partnership  can  be  further  leveraged  to  address 
a  number  of  key  telecommunications  initiatives, 
including  efforts  to: 

D  efinean  appropriate  threshold  for  security 

D  H  S  will  work  with  industry  to  define  an 
appropriate  security  threshold  for  the  sector  and 
develop  a  set  of  requirements  derived  from  that 
definition.  D  H  S  will  work  with  industry  to  close 
the  gap  between  respective  security  expectations 
and  requirements.  Reaching  agreement  on  a 
methodology  for  ensuring  physical  diversity  is  a 
key  element  of  this  effort. 

E  xpand  infrastructure  diverse  routing  capability 

D  H  S  will  leverage  and  enhance  the  government's 
capabilities  to  define  and  map  the  overall  telecom¬ 
munications  architecture.  This  effort  will  identify 
critical  intersections  among  the  various  infrastruc¬ 
tures  and  lead  to  strategies  that  better  address 
security  and  reliability. 

Understand  the  risks  associated  with  vulnerabilitiesofthe 
telecommunications  infrastructure 

The  telecommunications  infrastructure,  including 
the  PST  N  ,  the  I  nternet,  and  enterprise  networks, 
provides  essential  communications  for  governments 
at  all  levels  and  other  critical  infrastructures.  D  H  S 
will  work  with  the  private  sector  to  conduct  studies 
to  understand  physical  vulnerabilities  within  the 
telecommunications  infrastructure  and  their  associ¬ 
ated  risks.  Studies  will  focus  on  facilities  where 
many  different  types  of  equipment  and  multiple 
carriers  are  concentrated. 

C  oordinatewith  key  allies  and  trading  partners 

M  ore  than  ever  our  N  ation  has  a  common  reliance 
on  vital  communications  circuits  and  processes  with 
our  key  allies  and  trading  partners.  D  H  S  will  work 
with  other  nations  to  consider  innovative  communi¬ 
cations  paths  that  provide  priority  communications 
processes  to  link  our  governments,  global 
industries,  and  networks  in  such  a  manner  that 
vital  communications  are  assured. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  49 


ENERGY 


E  nergy  drives  the  foundation  of  many  of  the 
sophisticated  processes  at  work  in  American  society 
today.  It  is  essential  to  our  economy,  national  defense, 
and  quality  of  life. 

The  energy  sector  is  commonly  divided  into  two 
segments  in  the  context  of  critical  infrastructure 
protection:  electricity  and  oil  and  natural  gas.  The  elec¬ 
tric  industry  services  almost  130  million  households 
and  institutions.  The  United  States  consumed  nearly 
3.6  trillion  kilowatt  hours  in  2001.  Oil  and  natural  gas 
facilities  and  assets1  are  widely  distributed,  consisting 
of  more  than  300,000  producing  sites,  4,000  off-shore 
platforms,  more  than  600  natural  gas  processing  plants, 
153  refineries,  and  more  than  1,400  product  terminals, 
and  7,500  bulk  stations. 

ELECTRICITY 

A I  most  every  form  of  productive  activity—  whether  in 
businesses,  manufacturing  plants,  schools,  hospitals,  or 
homes—  requires  electricity.  E  lectricity  is  also  necessary 
to  produce  other  forms  of  energy,  such  as  refined  oil. 
Were  a  widespread  or  long-term  disruption  of  the 
power  grid  to  occur,  many  of  the  activities  critical  to  our 
economy  and  national  defense— including  those  associ¬ 
ated  with  response  and  recovery— would  be  impossible. 


T  he  N  orth  A  merican  electric  system  is  an 
interconnected,  multi-nodal  distribution  system  that 
accounts  for  virtually  all  the  electricity  supplied  to 
the  United  States,  C anada,  and  a  portion  of  Baja 
C  alifornia  N  orte,  M  exico.  T  he  physical  system  consists 
of  three  major  parts:  generation,  transmission  and 
distribution,  and  control  and  communications. 

Generation  assets  include  fossil  fuel  plants, 
hydroelectric  dams,  and  nuclear  power  plants. 

T ransmission  and  distribution  systems  link  areas  of  the 
national  grid.  D  istribution  systems  manage  and  control 
the  distribution  of  electricity  into  homes  and  busi¬ 
nesses.  Control  and  communications  systems  operate 
and  monitor  critical  infrastructure  components. 

I  n  addition  to  these  components,  the  electric 
infrastructure  also  comprises  ancillary  facilities  and 
systems  that  guarantee  fuel  supplies  necessary  to 
support  electricity  generation,  some  of  which  involve 
the  handling  of  hazardous  materials.  T  he  electricity 
sector  also  depends  heavily  on  other  critical  infrastruc¬ 
tures  for  power  generation,  such  as  telecommunications 
and  transportation. 

T  he  N  orth  A  merican  electric  system  is  the  world's 
most  reliable,  a  fact  that  can  be  attributed  to  industry- 
led  efforts  to  identify  single  points  of  failure  and 
system  interdependencies,  and  institute  appropriate 
back-up  processes,  systems,  and  facilities. 

After  N  ew  York's  power  blackout  in  1965,  the  industry 
established  the  N  orth  American  E  lectric  Reliability 
Council  (N  ERC)  to  develop  guidelines  and  procedures 
for  preventing  similar  incidents.  I\l  E  RC  is  a  nonprofit 
corporation  made  up  of  10  regional  reliability  councils, 
whose  voluntary  membership  represents  all  segments 
of  the  electricity  industry,  including  public  and  private 
utilities  from  the  U.S.  and  Canada. Through  N  E  RC , 
the  electricity  sector  coordinates  programs  to  enhance 
security  for  the  electricity  industry. 

T  he  electricity  sector  is  highly  regulated  even  as  the 
industry  is  being  restructured  to  increase  competition. 
The  Federal  Energy  Regulatory  Commission  (FERC) 
and  state  utility  regulatory  commissions  regulate  some 
of  the  activities  and  operations  of  certain  electricity 
industry  participants. T  he  N  uclear  Regulatory 
C  ommission  (N  RC )  regulates  nuclear  power  reactors 
and  other  civilian  nuclear  facilities,  materials, 
and  activities.2 


50  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


E  lectricity  Sector  C  hallenges 

The  electricity  sector  is  highly  complex,  and  its 
numerous  component  assets  and  systems  span  the 
N  orth  A  merican  continent.  M  any  of  the  sector's  key 
assets,  such  as  generation  facilities,  key  substations,  and 
switchyards,  present  unique  protection  challenges. 

Increased  competition  and  structural  changes  currently 
taking  place  within  the  sector  may  alter  security 
incentives  and  responsibilities  of  electricity  market 
participants.  T  hese  stakeholders  are  diverse  in  size, 
capabilities,  and  focus.  Currently,  individual  companies 
pay  for  levels  of  protection  that  are  consistent  with 
their  resources  and  customer  expectations.  T ypically, 
these  companies  seek  to  recover  the  costs  of  new 
security  investments  through  proposed  rate  or  price 
increases.  U  nder  current  federal  law,  however,  there 
is  no  assurance  that  electricity  industry  participants 
would  be  allowed  to  recover  the  costs  of  federally 
mandated  security  measures  through  such  rate  or 
price  increases. 

Another  challenge  for  the  electricity  industry  is 
effective,  sector-wide  communications.  T  he  owners  and 
operators  of  the  electric  system  are  a  large  and  hetero¬ 
geneous  group.  I  ndustry  associations  serve  as  clearing 
houses  for  industry- related  information,  but  not  all 
industry  owners  and  operators  belong  to  such  organi¬ 
zations.  Data  needed  to  perform  thorough  analyses  on 
the  infrastructure's  interdependencies  is  not  readily 
available.  A  focused  analysis  of  time- phased  effects  of 
one  infrastructure  on  another,  including  loss  of  opera¬ 
tions  metrics,  would  help  identify  dependencies  and 
establish  protection  priorities  and  strategies. 

For  certain  transmission  and  distribution  facilities, 
providing  redundancy  and  increasing  generating 
capacity  provide  greater  reliability  of  electricity  service. 
FI  owever,  this  approach  faces  several  challenges.  L  ong 
lead  times,  possible  denials  of  rights-of-way,  state  and 
local  siting  requirements,  "not- in- my- backyard" 
community  perspectives,  and  uncertain  rates  of  return 
when  compared  to  competing  investment  needs  are 
hurdles  that  may  prevent  owners  and  operators  of  elec¬ 
tricity  facilities  from  investing  sufficiently  in  security 
and  service  assurance  measures. 

Building  a  less  vulnerable  grid  represents  another 
option  for  protecting  the  national  electricity  infrastruc¬ 
ture.  Work  is  ongoing  to  develop  a  national  R&  D 
strategy  for  the  electricity  sector.  Additionally,  FE  RC 
has  developed  R&  D  guidelines,  and  the  D  epartment 
of  E  nergy’s  (D  oE ’s)  N  ational  G  rid  Study  contains 
recommendations  focused  on  enhancing  physical  and 
cyber  security  for  the  transmission  system. 


E  lectricity  Sector  I  nitiatives 

The  electricity  industry  has  a  history  of  taking  proac¬ 
tive  measures  to  assure  the  reliability  and  availability  of 
the  electricity  system.  Individual  enterprises  also  work 
actively  in  their  communities  to  address  public  safety 
issues  related  to  their  systems  and  facilities.  Since 
September  11,  2001,  the  sector  has  reviewed  its  secu¬ 
rity  guidelines  and  initiated  a  series  of  intra-industry 
working  groups  to  address  specific  aspects  of  security. 

It  has  created  a  utility-sector  security  committee  at 
the  chief  executive  officer  level  to  enhance  planning, 
awareness,  and  resource  allocation  within  the  industry. 

T  he  sector  as  a  whole,  with  N  E  RC  as  the  sector 
coordinator,  has  been  working  in  collaboration  with 
DOE  since  1998  to  assess  its  risk  posture  in  light  of 
the  new  threat  environment,  particularly  with  respect 
to  the  electric  system’s  dependence  on  information 
technology  and  networks.  I  n  the  process,  the  sector  has 
created  an  awareness  program  that  includes  a  "Business 
Casefor  Action  "for  industry  senior  executives,  a 
strategic  reference  document,  'An  Approach  to  Action  for 
the E lehtric Power  Sector,"  and  security  guidelines  related 
to  physical  and  cyber  security. 

W  ith  respect  to  managing  security  information,  the 
sector  has  established  an  indications,  analysis,  and 
warning  program  that  trains  utilities  on  incident 
reporting  and  alert  notification  procedures.  T  he  sector 
has  also  developed  threat  alert  levels  for  both  physical 
and  cyber  events,  which  include  action-response 
guidelines  for  each  alert  level.  T  he  industry  has  also 
established  an  I  SAC  to  gather  incident  information, 
relay  alert  notices,  and  coordinate  daily  briefs  between 
the  federal  government  and  electric  grid 
operators  around  the  country. 

Power  management  control  rooms  are  probably  the 
most  protected  aspect  of  the  electrical  network. 

N  ERC 's  guidelines  require  a  backup  system  and/or 
manual  work-arounds  to  bypass  damaged  systems. 
FERC  is  also  working  with  the  sector  to  develop  a 
common  set  of  security  requirements  for  all  enterprises 
in  the  competitive  electric  supply  market. 

Additional  electricity  sector  protection  initiatives 
include  efforts  to: 

I  dentify  equipment  stock  pile  requirements 

D  FI  S  and  D  oE  will  work  with  the  electricity  sector 
to  inventory  components  and  equipment  critical  to 
electric- system  operations  and  to  identify  and  assess 
other  approaches  to  enhance  restoration  and 
recovery  to  include  standardizing  equipment  and 
increasing  component  interchangeability. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  51 


R  e-  evaluate  and  adjust  nationwide  protection  planning, 
system  restoration,  and  recovery  in  response  to  attacks 

T  he  electric  power  industry  has  an  excellent  process 
and  record  of  reconstitution  and  recovery  from 
disruptive  events.  Jointly,  industry  and  government 
need  to  evaluate  this  system  and  its  processes  to 
support  the  evolution  from  a  local  and  regional 
system  to  an  integrated  national  response  system. 

D  H  S  and  D  oE  will  work  with  the  electricity  sector 
to  ensure  that  existing  coordination  and  mutual  aid 
processes  can  effectively  and  efficiently  support 
protection,  response,  and  recovery  activities  as  the 
structure  of  the  electricity  sector  continues  to  evolve. 

D  eve/ op  strategies  to  reduce  vulnerabilities 

D  H  S  and  D  oE  will  work  with  state  and  local 
governments  and  the  electric  power  industry  to 
identify  the  appropriate  levels  of  redundancy  of 
critical  parts  of  the  electric  system,  as  well  as 
requirements  for  designing  and  implementing 
redundancy  in  view  of  the  industry’s  realignment 
and  restructuring  activities. 

D  evelop  standardized  guidelines  for  physical 
security  programs 

D  H  S  and  D  0  E  will  work  with  the  sector  to  define 
consistent  criteria  for  criticality,  standard  approaches 
for  vulnerability  and  risk  assessments  for  critical 
facilities,  and  physical  security  training  for  electricity 
sector  personnel. 

OIL  &  NATURAL  GAS 

The  oil  and  natural  gas  industries  are  closely  inte¬ 
grated.  T  he  oil  infrastructure  consists  of  five  general 
components:  oil  production,  crude  oil  transport, 
refining,  product  transport  and  distribution,  and 
control  and  other  external  support  systems.  Oil  and 
natural  gas  production  include:  exploration,  field  devel¬ 
opment,  on-  and  offshore  production,  field  collection 
systems,  and  their  supporting  infrastructures.  C  rude  oil 
transport  includes  pipelines  (160,000  miles),  storage 
terminals,  ports,  and  ships.  T  he  refinement  infrastruc¬ 
ture  consists  of  about  150  refineries  that  range  in  size 
and  production  capabilities  from  5,000  to  over  500,000 
barrels  per  day.  T ransport  and  distribution  of  oil 
includes  pipelines,  trains,  ships,  ports,  terminals  and 
storage,  trucks,  and  retail  stations. 

The  natural  gas  industry  consists  of  three  major 
components:  exploration  and  production,  transmission, 
and  local  distribution.  T he  U.S.  produces  roughly  20 
percent  of  the  world's  natural  gas  supply.  T  here  are 
278,000  miles  of  natural  gas  pipelines  and  1,119,000 
miles  of  natural  gas  distribution  lines  in  the  U.S. 


D  istribution  includes  storage  facilities,  gas  processing, 
liquid  natural  gas  facilities,  pipelines,  citygates,  and 
liquefied  petroleum  gas  storage  facilities.  C  itygates  are 
distribution  pipeline  nodes  through  which  gas  passes 
from  interstate  pipelines  to  a  local  distribution  system. 
N  atural  gas  storage  refers  to  underground  aquifers, 
depleted  oil  and  gas  fields,  and  salt  caverns. 

The  pipeline  and  distribution  segments  of  the  oil  and 
natural  gas  industries  are  highly  regulated.  O  versight 
includes  financial,  safety,  and  siting  regulations.  The 
exploration  and  production  side  of  the  industry  is  less 
regulated,  but  is  affected  by  safety  regulations  and 
restrictions  concerning  property  access. 

O  il  and  N  atural  G  as  Sector  C  hallenges 

Protection  of  critical  assets  requires  both  heightened 
security  awareness  and  investment  in  protective  equip¬ 
ment  and  systems.  O  ne  serious  issue  is  the  lack  of 
metrics  to  determine  and  justify  corporate  security 
expenditures.  I  n  the  case  of  natural  disasters  or 
accidents,  there  are  well-established  methods  for 
determining  risks  and  cost-effective  levels  of  invest¬ 
ments  in  protective  equipment,  systems,  and  methods 
for  managing  risk  (e.g.,  insurance).  It  is  not  clear  what 
levels  of  security  and  protection  are  appropriate  and 
cost  effective  to  meet  the  risks  of  terrorist  attack. 

T  he  first  government  responders  to  a  terrorist  attack 
on  most  oil  and  natural  gas  sector  facilities  will  be 
local  police  and  fire  departments.  In  general,  these 
responders  need  to  improve  their  capabilities  and 
preparedness  to  confront  well-planned,  sophisticated 
attacks,  particularly  those  involving  C  BR  weapons. 
Fortunately,  because  of  public-safety  requirements 
related  to  their  operations  and  facilities,  the  oil  and 
natural  gas  industries  have  substantial  protection 
programs  already  in  place. 

Q  uick  action  to  repair  damaged  infrastructure  in  an 
emergency  can  be  impeded  by  a  number  of  hurdles, 
including  the  long  lead  time  needed  to  obtain  local, 
state,  and  federal  construction  permits  or  waivers; 
requirements  for  environmental  reviews  and  impact 
statements;  and  lengthy  processes  for  obtaining 
construction  rights-of-way  for  the  placement  of 
pipelines  on  adjoining  properties  if  a  new  path 
becomes  necessary.  T  he  availability  of  necessary 
materials  and  equipment,  and  the  uniqueness  of  such 
equipment  are  also  impediments  to  rapid  reconstitution 
of  damaged  infrastructure. 

The  current  system  for  locating  and  distributing 
replacement  parts  needs  to  be  enhanced  significantly. 

T  he  components  themselves  range  from  state-of-the- 
art  systems  to  mechanisms  that  are  decades  old.  W  hile 


52  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


newer  systems  are  standardized,  many  of  the  older 
components  are  unique  and  must  be  custom- manufac¬ 
tured.  M  oreover,  there  is  extensive  variation  in  size, 
ownership,  and  security  across  natural  gas  facilities. 

T  here  are  also  a  large  number  of  natural  gas  facilities 
scattered  over  broad  geographical  areas—  a  fact  that 
complicates  protection. 

0  il  and  N  atural  G  as  Sector  I  nitiatives 

Oil  and  natural  gas  sector  protection  initiatives  include 
efforts  to: 

Plan  and  invest  in  research  and  development  for  the  oil 
and  gas  industry  to  enhance  robustness  and  reliability 

Utilizing  the  federal  government’s  national  scientific 
and  research  capabilities,  DH  S  and  DoE  will  work 
with  oil  and  natural  gas  sector  stakeholders  to 
develop  an  appropriate  strategy  for  research  and 
development  to  support  protection,  response,  and 
recovery  requirements. 

D  eve/op  strategies  to  reduce  vulnerabilities 

D  H  S  and  D  oE  will  work  with  state  and  local 
governments  and  industry  to  identify  the  appro¬ 
priate  levels  of  redundancy  of  critical  components 
and  systems,  as  well  as  requirements  for  designing 
and  enhancing  reliability. 

D  eve/op  standardized  guidelines  for  physical  security 
programs 

D  H  S  and  D  oE  will  work  with  the  oil  and  natural 
gas  industry  representatives  to  define  consistent 
criteria  for  criticality,  standard  approaches  for 


vulnerability  and  risk  assessments  for  various 
facilities,  and  physical  security  training  for 
industry  personnel. 

D  evefop  guidelines  for  measures  to  reconstitute  capabilities 
of  individual  fadlitiesand  systems 

D  H  S  and  D  oE  will  convene  an  advisory  task  force 
of  industry  representatives  from  the  sector, 
construction  firms,  equipment  suppliers,  oil¬ 
engineering  firms,  state  and  local  governments,  and 
federal  agencies  to  identify  appropriate  planning 
requirements  and  approaches. 

D  evefop  a  national  system  for  locating  and  distributing 
critical  components  in  support  of  response  and  recovery 
activities 

D  H  S  and  DoE  will  work  with  industry  to  develop 
regional  and  national  programs  for  identifying  spare 
parts,  requirements,  notifying  parties  of  their 
availability,  and  distributing  them  in  an  emergency. 


1  Pipelines  that  transport  oil  and  gas  supplies  are  components 
of  the  transportation  sector's  critical  infrastructure  and  are 
regulated  by  the  D  epartment  of  T ransportation  (D  oT )  for 
safety  purposes.  T  heir  protection  is  discussed  in  further  detail 
on  pages  58-59  of  the  T ransportation  Sector  Section  of  this 
document. 

2  N  uclear  power  plants  are  an  important  component  of  the 
energy  sector's  critical  infrastructure.  Because  of  the  potential 
public  health  and  safety  consequences  an  attack  on  a  nuclear 
facility  could  cause,  specific  issues  related  to  their  protection 
areincluded  on  page  74  of  the  Protecting  Key  4  ssets  chapter  of 
this  document. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  53 


T  RAN  S  P  O  RTAT  ION 


T  he  transportation  sector  consists  of  several  key 
modes:  aviation,  maritime  traffic,  rail,  pipelines,  high¬ 
ways,  trucking  and  busing,  and  public  mass  transit.  T  he 
diversity  and  size  of  the  transportation  sector  makes  it 
vital  to  our  economy  and  national  security,  including 
military  mobilization  and  deployment.  Asa  whole,  its 
infrastructure  is  robust,  having  been  developed  over 
decades  of  both  private  and  public  investment. 

T ogether  the  various  transportation  modes  provide 
mobility  of  our  population  and  contribute  to  our 
much-cherished  individual  freedom.  The  transporta¬ 
tion  infrastructure  is  also  convenient.  Americans  rely 
on  its  easy  access  and  reliability  in  their  daily  lives. 

I  nterdependencies  exist  between  transportation  and 
nearly  every  other  sector  of  the  economy.  C  onsequently, 
a  threat  to  the  transportation  sector  may  impact  other 
industries  that  rely  on  it.  Threat  information  affecting 
transportation  modes  must  be  adequately  addressed 
through  communication  and  coordination  among 
multiple  parties  who  use  or  rely  on  these  systems. 

AVIATION 

The  aviation  mode  is  vast,  consisting  of  thousands  of 
entry  points.  It  also  has  symbolic  value,  representing 
the  freedom  of  movement  that  A  mericans  value  so 
highly  as  well  as  the  technological  and  industrial 


prowess  that  have  made  the  U  nited  States  a  world 
power.  T  he  N  ation’s  aviation  system  consists  of  two 
main  parts: 

•  A  irports  and  the  associated  assets  needed  to  support 
their  operations,  including  the  aircraft  that  they 
serve;  and 

•  Aviation  command,  control,  communications, 
and  information  systems  needed  to  support  and 
maintain  safe  use  of  our  national  airspace. 

Before  September  11,  the  security  of  airports  and  their 
associated  assets  was  the  responsibility  of  private 
carriers  and  state  and  local  airport  owners  and 
operators.  I  n  the  months  following  the  September  11 
attacks,  Congress  passed  legislation  establishing  the 
Transportation  Security  Administration  as  the 
responsible  authority  for  assuring  aviation  security. 

Aviation  M  odeC  hallenges 

As  the  events  of  September  11  illustrated,  aviation's 
vital  i  mportance  to  the  U  .S.  economy  and  the  freedom 
it  provides  our  citizens  make  its  protection  an  impor¬ 
tant  national  priority.  Aviation  faces  several  unique 
protection  challenges.  Its  distribution  and  open  access 
through  thousands  of  entry  points  at  home  and  abroad 
make  it  difficult  to  secure.  Furthermore,  components  of 
the  aviation  infrastructure  are  not  only  attractive 


54  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


terrorist  targets,  but  also  serve  as  potential  weapons 
to  be  exploited.  T ogether,  these  factors  make  the  U  .S. 
aviation  infrastructure  a  potential  target  for  future 
terrorist  strikes. 

Additional  unique  protection  challenges  for 
aviation  include: 

•  Volume  U.S.  air  carriers  transport  millions  of 
passengers  every  day  and  at  least  twice  as  many  bags 
and  other  cargo. 

•  L  i  mi  ted  capabilities  and  available  space  C  urrent 
detection  equipment  and  methods  are  limited  in 
number,  capability,  and  ease  of  use. 

•  T  /  me-  sensitive  cargo:  "Just-in-time"  delivery  of 
valuable  cargo  is  essential  for  many  businesses—  any 
significant  time  delay  in  processing  and  transporting 
such  cargo  would  negatively  affect  the  U  .5. 
economy. 

•  Security  versus  convenience  M  aintaining  security 
while  limiting  congestion  and  delays  complicates 
the  task  of  security  and  has  important  financial 
implications. 

•  Accessibility:  M  ost  airports  are  open  to  the  public; 
their  facilities  are  close  to  public  roadways  for 
convenience  and  to  streamline  access  for  vehicles 
delivering  passengers  to  terminals. 

A  nother  concern  for  the  aviation  industry  is  the 
additional  cost  of  increased  security  during  sustained 
periods  of  heightened  alert.  Since  September  11,  2001, 
airports  across  the  country  have-in  effect-been  working 
at  surge  capacity  to  meet  the  security  requirements  of 
the  current  threat  environment.  Some  cash-strapped 
operators  must  now  balance  providing  higher  levels  of 
security  with  staying  in  business. 

Aviation  M  ode  I  nitiatives 

A  irport  security  failures  on  September  11  have  placed 
the  aviation  industry  under  intense  public  scrutiny.  To 
regain  the  public's  confidence  in  air  travel,  public  and 
private  organizations  have  made  substantial  invest¬ 
ments  to  increase  airport  security.  M  uch  work  remains. 
D  H  S,  as  the  federal  lead  department  for  the  trans¬ 
portation  sector,  will  work  with  D  oT,  industry,  and 
state  and  local  governments  to  organize,  plan,  and 
implement  needed  protection  activities. 

Aviation  mode  protection  initiatives  include  efforts  to: 

Identify  vulnerabilities,  interdependences,  and 
remediation  requirements 

D  H  S  and  D  oT  will  work  with  representatives  from 
state  and  local  governments  and  industry  to 
implement  or  facilitate  risk  assessments  to  identify 


vulnerabilities,  interdependencies,  and  remediation 
requirements  for  operations  and  coordination- center 
facilities  and  systems,  such  as  the  need  for  redun¬ 
dant  telecommunications  for  air  traffic  command 
and  control  centers. 

I  dentify  potential  threats  to  passengers 

D  H  S  and  D  oT  will  work  with  airline  and  airport 
security  executives  to  develop  or  facilitate  new 
methods  for  identifying  likely  human  threats  while 
respecting  constitutional  freedoms  and  privacy. 

I  mprove  security  at  key  points  of  access 

D  H  S  and  D  oT  will  work  with  airline  and  airport 
security  executives  to  tighten  security  or  facilitate 
increased  security  at  restricted  access  points  within 
airport  terminal  areas,  as  well  as  the  perimeter  of 
airports  and  associated  facilities,  including 
operations  and  coordination  centers. 

I  n crease  cargo  screening  capabilities 

D  H  S  and  D  oT  will  work  with  airline  and  airport 
security  officials  to  identify  and  implement  or  facili¬ 
tate  technologies  and  processes  to  enhance  airport 
baggage- screening  capacities. 

I  dentify  and  improve  detection  technologies 

D  H  S  and  D  oT  will  work  with  airline  and  airport 
security  executives  to  implement  or  facilitate 
enhanced  technologies  for  detecting  explosives. 

Such  deviceswill  mitigate  the  impact  of  increased 
security  on  passenger  check-in  efficiency  and 
convenience,  and  also  provide  a  more  effective  and 
efficient  means  of  assuring  vital  aviation  security. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  55 


PASSENGER  RAIL 
AND  RAILROADS 

D  uring  every  hour  of  every  day,  trains  traverse  the 
United  States,  linking  producers  of  raw  materials  to 
manufacturers  and  retailers.  T  hey  carry  mining,  manu¬ 
facturing,  and  agriculture  products;  liquid  chemicals 
and  fuels;  and  consumer  goods.  T rains  carry  40  percent 
of  intercity  freight—  a  much  larger  portion  than  is 
moved  by  any  other  single  mode  of  transportation. 

A  bout  20  percent  of  that  freight  is  coal,  a  critical 
resource  for  the  generation  of  electricity.  M  ore  than 
20  million  intercity  travelers  use  the  rail  system  annu¬ 
ally,  and  45  million  passengers  ride  trains  and  subways 
operated  by  local  transit  authorities.  Securing  rail- 
sector  assets  is  critical  to  protecting  U.S.  commerce 
and  the  safety  of  travelers. 

Rail  M  odeC  hallenges 

0  ur  N  ation's  railway  system  is  vast  and  complex,  with 
multiple  points  of  entry.  D  ifferences  in  design,  struc¬ 
ture,  and  purpose  of  railway  stations  complicate  the 
sector's  overall  protection  framework.  T  he  size  and 
breadth  of  the  sector  make  it  difficult  to  react  to 
threats  effectively  or  efficiently  in  all  scenarios.  T  his 
fact  complicates  protection  efforts,  but  it  also  offers 
certain  mitigating  potential  in  the  event  of  a  terrorist 
attack.  For  example,  trains  are  confined  to  specific 
routes  and  are  highly  controllable.  If  hijacked,  a  train 
can  be  shunted  off  the  mainline  and  rendered  less  of  a 
threat.  Similarly,  the  loss  of  a  bridge  or  tunnel  can 


impact  traffic  along  major  corridors;  however,  the 
potential  for  national-level  disruptions  is  limited. 

T  he  greater  risk  is  associated  with  rail  transport  of 
hazardous  materials.  Freight  railways  often  carry 
hazardous  materials  that  are  essential  to  other  sectors 
and  public  services.  The  decision-making  process 
regarding  their  transport  is  complex  and  requires  close 
coordination  between  industry  and  government. 

A  sector-wide  information  sharing  process  could  help 
prevent  over- reactive  security  measures,  such  as 
restricting  the  shipment  of  critical  hazardous  materials 
nationwide  as  a  blanket  safety  measure  in  response  to  a 
localized  incident. 

Security  solutions  to  the  container  shipping  challenge 
should  recognize  that,  in  many  cases,  commerce, 
including  essential  national  security  materials,  must 
continue  to  flow.  Stifling  commerce  to  meet  security 
needs  simply  swaps  one  consequence  of  a  security 
threat  for  another.  I  n  the  event  that  a  credible  threat 
were  to  necessitate  a  shutdown,  well -developed  conti¬ 
nuity  of  operations  procedures  can  mitigate  further 
unintentional  negative  consequences.  For  example, 
contingency  planning  can  help  determine  how  quickly 
commerce  can  be  resumed;  whether  rerouting  provides 
a  measure  of  protection;  or  what  specific  shipments 
should  be  exempt  from  a  shutdown,  such  as  national 
defense  critical  materials. 

A  n  additional  area  of  concern  is  the  marking  of 
container  cars  to  indicate  the  specific  type  of  hazardous 
materials  being  transported.  D  uring  an  emergency 
response,  placards  on  rail  cars  help  to  alert  first  respon¬ 
ders  to  hazardous  materials  they  may  encounter. 

P  lanners  must  take  care,  however,  to  devise  a  system 
of  markings  that  terrorists  cannot  easily  decipher. 

Like  the  aviation  sector,  the  rail  industry  also  faces  the 
additional  costs  of  sustaining  increased  security  during 
periods  of  heightened  alert.  Since  the  events  of 
September  11,  the  railroads  across  the  country  have- 
in  effect—  been  working  at  surge  capacity  to  meet  the 
security  requirements  of  the  increased  threat  environ¬ 
ment,  which  entails  assigning  overtime  and  hiring 
temporary  security  personnel.  Such  reservoirs  of 
capacity  are  costly  to  maintain.  N  evertheless,  the  rail 
sector  has  had  to  adopt  these  heightened  security  levels 
as  the  new  "normal"  state.  Some  cash-strapped  opera¬ 
tors  now  face  trade-offs  between  providing  increased 
levels  of  security  and  going  out  of  business. 

Railroads  have  well- developed  contingency  plans  and 
backups  for  dispatch,  control,  and  communications 
equipment  that  are  sufficient  for  localized  or  minor 
disruptions.  D  eveloping  this  type  of  backup  to  enable 


56  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


continuation  of  operations  after  a  cataclysmic  event  is 
problematic  given  the  costs  associated  with  extensive 
structural  enhancements. 

Rail  M  ode  I  initiatives 

T  he  rail  mode  has  been  working  actively  with  D  oT  to 
assess  the  risk  environment.  Asa  result,  it  has  devel¬ 
oped  a  comprehensive  modal  risk  assessment  and 
established  a  surface  transportation  ISAC  to  facilitate 
the  exchange  of  information  related  to  both  cyber  and 
physical  threats  specific  to  the  railroads. 

Since  September  11,  many  rail  operators  have  added 
investments  to  their  security  programs.  Additional  rail 
mode  protection  initiatives  include  efforts  to: 

D  eve/op  improved  decision-  making  criteria  regarding  the 
shipmen  t  of  haz  ardous  materials 

D  H  S  and  D  oT,  coordinating  with  other  federal 
agencies,  state  and  local  governments,  and  industry 
will  facilitate  the  development  of  an  improved 
process  to  assure  informed  decision-making  with 
respect  to  hazardous  materials  shipment. 

D  a/ el  op  technologies  and  procedures  to  screen  intermodal 
containers  and  passenger  baggage 

D  H  S  and  D  oT  will  work  with  sector  counterparts 
to  identify  and  explore  technologies  and  processes 
to  enable  efficient  and  expeditious  screening  of 
rail  passengers  and  baggage,  especially  at  inter¬ 
modal  stations. 

I  mprove  security  of  intermodal  transportation 

D  H  S  and  D  oT  will  work  with  sector  counterparts 
to  identify  and  facilitate  the  development  of 
technologies  and  procedures  to  secure  inter-modal 
containers  and  detect  threatening  content. 

D  H  S  and  D  oT  will  also  work  with  the  rail  industry 
to  devise  or  enable  a  hazardous  materials  identifica¬ 
tion  system  that  supports  the  needs  of  first 
responders,  yet  avoids  providing  terrorists  with  easy 
identification  of  a  potential  weapon. 

C  learly  delineate  rolesand  responsibilities  regarding 
surge  requirements 

DH  S  and  DoT  will  work  with  industry  to  delineate 
infrastructure  protection  rolesand  responsibilities  to 
enable  the  rail  industry  to  address  surge  requirements 
for  resources  in  the  case  of  catastrophic  events. 

C  osts  and  resource  allocation  remains  a  contentious 
issue  for  the  rail  sector.  DH  S  and  DoT  will  also 
convene  a  working  group  consisting  of  government 
and  industry  representatives  to  identify  options  for 
the  implementation  of  surge  capabilities,  including 
access  to  federal  facilities  and  capabilities  in 
extreme  emergencies. 


HIGHWAYS,  TRUCKING, 

AND  BUSING 

The  trucking  and  busing  industry  is  a  fundamental 
component  of  our  national  transportation  infrastruc¬ 
ture.  W  ithout  the  sector’s  resources,  the  movement  of 
people,  goods,  and  services  around  the  country  would 
be  greatly  impeded.  Components  of  this  infrastructure 
include  highways,  roads,  inter-modal  terminals, 
bridges,  tunnels,  trucks,  buses,  maintenance  facilities, 
and  roadway  border  crossings. 

H  ighways,  T rucking,  and  B using  M  ode 
C  hallenges 

Because  of  its  heterogeneity  in  size  and  operations 
and  the  multitude  of  owners  and  operators  nationwide, 
the  trucking  and  busing  infrastructure  is  highly 
resilient,  flexible,  and  responsive  to  market  demand. 

For  the  same  reason,  the  sector  is  fractionated  and 
regulated  by  multi plejurisdictions  at  state,  federal, 
and— sometimes— local  levels. The  size  and  pervasive 
nature  of  the  trucking  and  busing  infrastructure  pose 
significant  protection  challenges. 

T ransportation  choke  points  (e.g.,  bridges  and  tunnels, 
inter-modal  terminals,  border  crossings,  and  highway 
interchanges)  present  unique  protection  challenges. 

0  verall  understanding  of  infrastructure  choke  points  is 
limited.  Common  criteria  for  identifying  critical  choke 
points  are  therefore  difficult  to  establish.  We  must 
undertake  a  comprehensive,  systematic  effort  to  iden¬ 
tify  key  assets,  particularly  those  whose  destruction  or 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  57 


disruption  would  entail  significant  public  health  and 
safety  consequences  or  significant  economic  impact. 

Although  many  states  have  conducted  risk  assessments 
of  their  respective  highway  infrastructures,  no  true  basis 
for  comparison  among  them  exists  to  determine  relative 
criticality.  L  ikewise,  there  is  no  coordinated  mechanism 
for  assessing  choke- point  vulnerabilities  or  conducting 
and  evaluating  risk  mitigation  planning.  A  major  reason 
for  this  lack  of  synchronization  within  the  sector  is  a 
paucity  of  funds  to  promote  communication  among 
industry  members  and  facilitate  cooperation  for  joint 
protection  planning  efforts.  Asa  result,  the  sector  as  a 
whole  has  neither  a  coherent  picture  of  industry-wide 
risks,  nor  a  set  of  appropriate  security  criteria  on  which 
to  baseline  its  protection  planning  efforts,  such  as  what 
conditions  constitute  threats  for  the  sector,  or  standards 
for  infrastructure  protection  or  threat  reduction.  T  he 
sector’s  diverse  and  widely  distributed  constituency 
complicates  this  situation. 

G  iven  the  number  of  public  and  private  small -business 
owners  and  operators  in  this  sector,  the  cost  of  infra¬ 
structure  protection  is  also  a  major  challenge.  Like  the 
rail  mode,  in  addition  to  the  financial  concerns  associ¬ 
ated  with  new  security  investments,  highway,  trucking, 
and  busing  organizations  also  regard  the  possibility  of 
security- related  delays  at  border  crossings  as  a  potential 
problem  of  major  financial  significance. 

Another  challenge  is  the  way  in  which  sector  security 
incidents  are  handled  across  multiple  jurisdictions. 
Because  different  law  enforcement  agencies  differ  in 
their  approaches  to  crimes  like  truck  theft,  law  enforce¬ 
ment  responses  to  security  incidents  in  this  sector  are 
inconsistent  across  jurisdictional  lines. 

H  ighways,  Trucking,  and  Busing  M  ode 
Initiatives 

Like  the  other  major  transportation  modes,  the 
highways,  trucking,  and  busing  mode  has  assessed  its 
own  security  programs  in  light  of  the  September  11 
attacks.  H  owever,  the  sector’s  vast,  heterogeneous 
nature  requires  further  expanded  coordination  among 
stakeholder  organizations  to  assure  a  more  consistent, 
integrated  national  approach.  Additionally,  a  better 
understanding  of  the  overall  system  would  lead  to 
more  adaptable,  less  intrusive,  and  more  cost-effective 
security  processes.  H  ighways,  trucking,  and  busing 
protection  initiatives  include  efforts  to: 

Facilitate  comprehensive  risk,  threat,  and  vulnerability 
assessments 

D  H  S,  working  closely  with  D  oT  and  other  key 
sector  stakeholders,  will  facilitate  comprehensive  risk, 
threat,  and  vulnerability  assessments  for  this  mode. 


D  eve/op  guidelinesand  standard  criteria  for  identifying 
and  mitigating  chokepoints 

D  H  S,  working  with  D  oT  and  other  sector  key 
stakeholders,  will  develop  guidelinesand  standard 
criteria  for  identifying  and  mitigating  choke  points, 
both  nationally  and  regionally. 

H  arden  industry  infrastructureagainst  terrorism 
through  technology 

D  H  S  will  work  jointly  with  industry  and  state  and 
local  governments  to  explore  and  identify  potential 
technology  solutions  and  standards  that  will  support 
analysis  and  afford  better  and  more  cost  effective 
protection  against  terrorism. 

C  reate  national  transportation  operator  security  education 
and  awareness  programs 

D  H  S  and  D  oT  will  work  with  industry  to  create 
national  operator  security  education  and  awareness 
programs  to  provide  the  foundation  for  greater 
cooperation  and  coordination  within  this  highly 
diverse  mode. 

PIPELINES 

T  he  U  nited  States  has  a  vast  pipeline  industry, 
consisting  of  many  hundreds  of  thousands  of  miles  of 
pipelines,  many  of  which  are  buried  underground. 

T  hese  lines  move  a  variety  of  substances  such  as  crude 
oil,  refined  petroleum  products,  and  natural  gas. 

Pipeline  facilities  already  incorporate  a  variety  of 
stringent  safety  precautions  that  account  for  the  poten¬ 
tial  effects  a  disaster  could  have  on  surrounding  areas. 

M  oreover,  most  elements  of  pipeline  infrastructures 
can  be  quickly  repaired  or  bypassed  to  mitigate  local¬ 
ized  disruptions.  D  estruction  of  one  or  even  several 
of  its  key  components  would  not  disrupt  the  entire 
system.  As  a  whole,  the  response  and  recovery  capabili¬ 
ties  of  the  pipeline  industry  are  well  proven,  and  most 
large  control -center  operators  have  established 
extensive  contingency  plans  and  backup  protocols. 

Pipeline  M  ode  C  hallenges 

Pipelines  are  not  independent  entities,  but  rather 
integral  parts  of  industrial  and  public  service  networks. 
L  oss  of  a  pipeline  could  impact  a  wide  array  of  facili¬ 
ties  and  industrial  factories  that  depend  on  reliable  fuel 
delivery  to  operate. 

Several  hundred  thousand  miles  of  pipeline  span  the 
country,  and  it  is  not  realistic  to  expect  total  security 
for  all  facilities.  As  such,  protection  efforts  focus  on 
infrastructure  components  whose  impairment  would 
have  significant  effects  on  the  energy  markets  and  the 
economy  as  a  whole.  For  the  pipeline  industry, 


58  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


determining  what  to  protect  and  when  to  protect  it 
is  a  factor  in  cost-effective  infrastructure  protection. 

D  uring  periods  of  high  demand—  such  as  the  winter 
months—  pipeline  systems  typically  operate  at  peak 
capacity  and  are  more  important  to  the  facilities  and 
functions  they  serve. 

The  pipeline  industry  as  a  whole  has  an  excellent  safety 
record,  as  well  as  in-place  crisis  management  protocols 
to  manage  disruptions  as  they  occur.  N  evertheless,  many 
of  the  products  that  pipelines  deliver  are  inherently 
volatile.  H  ence,  their  protection  is  a  significant  issue. 

Pipelines  cross  numerous  state  and  local,  as  well  as 
international  jurisdictions. The  number  and  variety 
of  stakeholders  create  a  confusing,  and  sometimes 
conflicting,  array  of  regulations  and  security  programs 
for  the  industry  to  manage,  especially  with  respect  to 
the  ability  of  pipeline  facilities  to  recover,  reconstitute, 
and  re-establish  service  quickly  after  a  disruption. 

The  pipeline  industry’s  increasing  interdependencies 
with  the  energy  and  telecommunications  sectors  neces¬ 
sitate  cooperation  with  other  critical  infrastructures 
during  protection  and  response  planning.  Individually, 
companies  have  difficulty  assessing  the  broader  impli¬ 
cations  of  an  attack  on  their  critical  facilities.  T  hese 
interdependencies  call  for  cross- sector  coordination 
for  to  be  truly  responsive  to  national  concerns. 
Additionally,  some  issues  concerning  recovery  or  recon¬ 
stitution  will  require  at  least  regional  planning  within 
the  industry,  as  well  as  the  sharing  of  sensitive  business 
information  that  may  run  into  proprietary  concerns. 

Pipeline  M  ode  I  nitiatives 

H  istorically,  individual  enterprises  within  this  sector 
have  invested  in  the  security  of  their  facilities  to 


protect  their  ability  to  deliver  oil  and  gas  products. 
Representatives  from  major  entities  within  this  sector 
have  examined  the  new  terrorist  risk  environment.  Asa 
result,  they  have  developed  a  plan  for  action,  including 
industry-wide  information  sharing.  In  addition  to 
industry  efforts,  D  oT  has  developed  a  methodology  for 
determining  pipeline  facility  criticality  and  a  system  of 
recommended  protective  measures  that  are  synchro¬ 
nized  with  the  threat  levels  of  the  H  omeland  Security 
Advisory  System.  Additional  pipeline  mode  protection 
initiatives  include  efforts  to: 

D  eve/op  standard  reconstitution  protocols 

D  H  S,  in  collaboration  with  D  oE ,  D  oT,  and 
industry,  will  initiate  a  study  to  identify,  clarify, 
and  establish  authorities  and  procedures  as  needed 
to  reconstitute  facilities  as  quickly  as  possible  after 
a  disruption. 

D  eve/op  standard  security  assessment  and  threat 
deterrent  guidelines 

D  H  S,  in  collaboration  with  D  oE  and  D  oT,  will 
work  with  state  and  local  governments  and  the 
pipeline  industry  to  develop  consensus  security 
guidance  on  assessing  vulnerabilities,  improving 
security  plans,  implementing  specific  deterrent 
and  protective  actions,  and  upgrading  response  and 
recovery  plans  for  pipelines. 

Work  with  other  sectors  to  manage  risks  resulting  from 
interdependencies 

D  H  S,  in  collaboration  with  D  oE  and  D  oT,  will 
convene  cross- sector  working  groups  to  develop 
models  for  integrating  protection  priorities  and 
emergency  response  plans. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  59 


MARITIME 

The  maritime  shipping  infrastructure  includes  ports 
and  their  associated  assets,  ships  and  passenger  trans¬ 
portation  systems,  costal  and  inland  waterways,  locks, 
dams  and  canals,  and  the  network  of  railroads  and 
pipelines  that  connect  these  waterborne  systems  to 
other  transportation  networks.  T  here  are  361  seaports 
in  the  U  nited  States,  and  their  operations  range  widely 
in  size  and  characteristics. 

M  ost  ports  have  diverse  waterside  facilities  that  are 
owned,  operated,  and  accessed  by  diverse  entities.  State 
and  local  governments  control  some  port  authority 
facilities,  while  others  are  owned  and  operated  by 
private  corporations.  M  ost  ships  are  privately  owned 
and  operated.  C  argo  is  stored  in  terminals  at  ports  and 
loaded  onto  ships  or  other  vehicles  that  pass  through 
on  their  way  to  domestic  and  international  destina¬ 
tions.  DoD  has  also  designated  certain  commercial 
seaports  as  strategic  seaports,  which  provide  facilities 
and  services  needed  for  military  deployment. 

M  aritime  M  odeC  hallenges 

T  he  size,  diversity,  and  complexity  of  this  infrastructure 
make  the  inspection  of  all  vessels  and  cargo  that  passes 
through  our  ports  an  extremely  difficult  undertaking. 
Current  inspection  methods— both  physical  and  tech¬ 
nological—  are  limited  and  costly.  As  with  other  modes 


of  transportation  that  cross  international  borders,  we 
must  manage  the  tension  between  efficient  processing 
of  cargo  and  passengers  and  adequate  security. 

M  ajor  portions  of  the  maritime  industry’s  operations 
are  international  in  nature  and  are  governed  by  inter¬ 
national  agreements  and  multinational  authorities, 
such  as  the  International  M  aritime  0  rganization. 

N  egotiation  of  maritime  rules  and  practices  with 
foreign  governments  lies  within  the  purview  of  D  oS. 
Often  these  international  efforts  involve  extended 
negotiation  timelines. 

D  oT  currently  recommends  guidelines  for  passenger 
vessel  and  terminal  security,  including  passenger  and 
baggage  screening  and  training  of  crews.  T  he  industry 
requires  R&  D  for  cost-effective  technologies  for  the 
rapid  detection  of  explosives  and  other  hazardous 
substances,  as  well  as  for  new  vessel  designs  to  mini¬ 
mize  the  likelihood  of  a  ship  sinking  if  it  were  attacked. 

M  uch  of  the  port  system  represents  a  significant 
protection  challenge,  particularly  in  the  case  of  high 
consequence  cargo.  Physical  and  operational  security 
guidelines  have  undergone  a  comprehensive  review, 
from  which  D  oT  and  D  H  S  will  issue  guidance  and 
recommendations  for  appropriate  protective  actions. 

E  fforts  to  i  ncrease  the  security  of  the  mariti  me 
industry  must  also  consider  infrastructures  subject  to 


60  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


multi-agency  jurisdictions  and  the  international 
framework  in  which  the  industry  operates. 

M  aritime  M  ode  I  nitiatives 

Following  the  September  11  attacks,  initial  risk 
assessments  were  conducted  for  all  ports.  T  hese  assess¬ 
ments  have  helped  refine  critical  infrastructure  and  key 
asset  designations,  assess  vulnerabilities,  guide  the 
development  of  mitigation  strategies,  and  illuminate 
best  practices.  M  ost  port  authorities  and  private  facility 
owners  have  also  reexamined  their  security  practices. 
Based  on  these  preliminary  risk  assessments,  D  oT 
increased  vessel  notification  requirements  to  shift 
limited  resources  to  maintain  positive  control  of  move¬ 
ment  of  high-risk  vessels  carrying  high- consequence 
cargoes  and  large  numbers  of  passengers.  D  oT  and  the 
U .S.  C  oast  G  uard  have  also  established  a  Sea  M  arshal 
program  and  deployable  M  aritime  Safety  and  Security 
Teams  to  implement  these  activities. 

Additionally,  DoT  has  participated  in  efforts  to  expe¬ 
dite  compliance  with  existing  international  standards 
and  to  develop  additional  standards  to  enhance  port, 
vessel,  and  facility  security.  D  oT  is  also  working  with 
the  U.S.  C  ustoms  Service  to  implement  the  Container 
Security  I nitiative  to  ensure  the  security  of  the  shipping 
supply  chain.  Shippers  who  do  not  comply  with 
outlined  rules  and  regulations  will  be  subject  to 
greater  scrutiny  and  delays  when  entering  U  .S.  ports. 

Additional  maritime  mode  protection  initiatives 
include  efforts  to: 

Identify  vulnerabilities*  interdependences*  best  practices* 
and  remediation  requirements 

D  H  S  and  D  oT  will  undertake  or  facilitate 
additional  security  assessments  to  identify  vulnera¬ 
bilities  and  interdependencies,  enable  the  sharing  of 
share  best  practices,  and  issue  guidance  or  recom¬ 
mendations  on  appropriate  mitigation  strategies. 

D  evefop  a  plan  for  implementing  security  measures 
corresponding  to  varying  threat  levels 

D  H  S  and  D  oT  will  work  closely  with  other 
appropriate  federal  departments  and  agencies,  port 
security  committees,  and  private- sector  owners  and 
operators  to  develop  or  facilitate  the  establishment 
of  security  plans  to  minimize  security  risks  to  ports, 
vessels,  and  other  critical  maritime  facilities. 

D  evefop  processes  to  enhance  maritime  domain  awareness 
and  gain  international  cooperation 

D  H  S  and  D  oT  will  work  closely  with  other 
appropriate  federal  departments  and  agencies,  port 
security  committees,  and  port  owners  and  operators, 
foreign  governments,  international  organizations, 


and  commercial  firms  to  establish  a  means  for 
identifying  potential  threats  at  ports  of  embarkation 
and  monitor  identified  vessels,  cargo,  and  passengers 
en  route  to  the  U.S. 

D  evefop  a  template  for  improving  physical  and 
operational  port  security 

D  H  S  and  D  oT  will  collaborate  with  appropriate 
federal  departments  and  agencies  and  port  owners  and 
operators  to  develop  a  template  for  improving  physical 
and  operational  port  security.  A  list  of  possible  guide¬ 
lines  will  include  workforce  identification  measures, 
enhanced  port- facility  designs,  vessel  hardening  plans, 
standards  for  international  container  seals,  guidance 
for  the  research  and  development  of  noninvasive 
security  and  monitoring  systems  for  cargo  and  ships, 
real-time  and  trace- back  capability  information  for 
containers,  prescreening  processes  for  high-risk 
containers,  and  recovery  plans.  Activities  will  include 
reviewing  the  best  practices  of  other  countries. 

D  evefop  security  and  protection  guidelines  and 
technologies  for  cargo  and  passenger  ships 

D FI  S  and  DoT  will  work  with  international  maritime 
organizations  and  industry  to  study  and  develop 
appropriate  guidelines  and  technology  requirements 
for  the  security  of  cargo  and  passenger  ships. 

I  mprove  waterway  security 

D  FI  S  and  D  oT,  working  with  state  and  local 
government  owners  and  operators,  will  develop 
guidelines  and  identify  needed  support  for 
improving  security  of  waterways,  such  as  developing 
electronic  monitoring  systems  for  waterway  traffic; 
modeling  shipping  systems  to  identify  and  protect 
critical  components;  and  identifying  requirements 
and  procedures  for  periodic  waterway  patrols. 

MASS  TRANSIT  SYSTEMS 

E  ach  year  passengers  take  approximately  9.5  billion 
trips  on  public  transit.  I  n  fact,  mass  transit  carries  more 
passengers  in  a  single  day  than  air  or  rail  transportation. 
If  the  effect  on  air  transportation  resulting  from  the 
September  11  attacks  is  an  indicator,  then  a  terrorist 
attack  on  a  major  mass  transit  system  could  have  a 
significant  regional  and  national  economic  impact. 

M  ass  transit  systems  are  designed  to  be  publicly 
accessible.  M  ost  are  owned  and  operated  by  state  and 
local  agencies.  A  city  relies  on  its  mass  transit  system 
to  serve  a  significant  portion  of  its  workforce  in 
addition  to  being  a  means  of  evacuation  in  case  of 
emergency.  Protection  of  mass  transit  systems  is, 
therefore,  an  important  requirement. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  61 


M  assT ransit  M  ode  C  hallenges 

M  ass  transit  is  regulated  by  various  agencies.  T  hese 
agencies  must  communicate  and  work  together  effec¬ 
tively  to  allow  transit  to  work  as  a  system  rather  than 
in  separate  modes.  M  ass  transit  is  funded  and  managed 
at  the  local  level,  and  operated  as  a  not-for-profit 
entity.  The  Federal  T ransit  Authority  has  limited 
legislative  authority  to  overseethe  security  planning 
and  operations  of  transit  systems. 

M  ass  transit  systems  were  designed  for  openness  and 
ease  of  public  access,  which  makes  monitoring  points 
of  entry  and  exit  difficult.  Protecting  them  is  also 
expensive.  T ransit  authorities  must  have  the  financial 
resources  to  respond  to  emergencies  and  maintain 
adequate  security  levels  to  deter  attacks  over  broad 
geographic  areas.  The  cost  of  implementing  new 
security  requirements  could  result  in  significant 
financial  consequences  for  the  industry. 


E  ach  city  and  region  has  a  unique  transit  system, 
varying  in  size  and  design.  N  o  one  security  program 
or  information  sharing  mechanism  will  fit  all  systems. 
D  espite  these  differences,  as  a  general  rule,  basic 
planning  factors  are  relatively  consistent  from  system 
to  system. 

M  assT  ransit  M  ode  I  initiatives 

Since  transit  is  localized  and  varies  significantly  in  size 
and  design  from  system  to  system,  identifying  critical 
guidelines  and  standards  for  planning  is  key  to  unifying 
mass  transit  security  activities.  Panels  in  theT ransit 
Cooperative  Research  Program  have  recommended 
and  are  overseeing  10  research  projects  in  the  areas  of 
prevention,  mitigation,  preparedness,  and  response. 
Their  recommendations  can  provide  additional  input 
to  the  development  of  these  planning  areas. 

Additional  mass  transit  protection  initiatives  include 
efforts  to: 

I  dentify  critical  planning  areas  and  develop  appropriate 
guidelines  and  standards 

DH  S,  working  closely  with  DoT  and  other  federal, 
state,  and  local  mass  transit  officials,  will  identify 
critical  planning  areas  and  develop  appropriate 
guidelines  and  standards  to  protect  mass  transit 
systems.  Such  critical  planning  areas  and  guidelines 
include  design  and  engineering  standards  for  facili¬ 
ties  and  rail  and  bus  vehicles;  emergency  guidance 
for  operations  staff;  screening  methods  and  training 
programs  for  operators;  security  planning  oversight 
standards;  mutual  aid  policies;  and  continuity  of 
operations  planning. 

Identify  protective  impedimentsand  implement  security 
enhancements 

D  FI  S,  working  closely  with  D  oT  and  mode 
representatives,  will  review  legal,  legislative,  and 
statutory  regimes  to  develop  an  overall  protective 
architecture  for  mass  transit  systems  and  to  identify 
impediments  to  implementing  needed  security 
enhancements. 

Work  with  other  sectors  to  manage  unique  risks  resulting 
from  interdependencies 

D  FI  S,  in  collaboration  with  D  oT,  will  convene 
cross- sector  working  groups  to  develop  models  for 
integrating  priorities  and  emergency  response  plans 
in  the  context  of  interdependencies  between  mass 
transit  and  other  critical  infrastructures. 


62  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


BANKING  AND  FINANCE 


T  he  banking  and  financial  services  sector  infrastructure 
consists  of  a  variety  of  physical  structures,  such  as 
buildings  and  financial  utilities,  as  well  as  human 
capital.  M  ost  of  the  industry’s  activities  and  operations 
take  place  in  large  commercial  office  buildings.  Physical 
structures  to  be  protected  house  retail  or  wholesale 
banking  operations,  financial  markets,  regulatory 
institutions,  and  physical  repositories  for  documents 
and  financial  assets.  Today's  financial  utilities,  such  as 


payment  and  clearing  and  settlement  systems,  are 
primarily  electronic,  although  some  physical  transfer  of 
assets  does  still  occur.  The  financial  utilities  infrastruc¬ 
ture  includes  such  electronic  devices  as  computers, 
storage  devices,  and  telecommunication  networks.  In 
addition  to  the  sector's  key  physical  components,  many 
financial  services  employees  have  highly  specialized 
skills  and  are,  therefore,  considered  essential  elements  of 
the  industry’s  critical  infrastructure. 

The  financial  industry  also  depends  on  continued 
public  confidence  and  involvement  to  maintain  normal 
operations.  Financial  institutions  maintain  only  a  small 
fraction  of  depositors’  assets  in  cash  on  hand.  If  deposi¬ 
tors  and  customers  were  to  seek  to  withdraw  their 
assets  simultaneously,  severe  liquidity  pressures  would 
be  placed  on  the  financial  system.  W  ith  this  in  mind, 
federal  safeguards  are  in  place  to  prevent  liquidity 
shortfalls.  In  times  of  crisis  or  disaster,  maintaining 
public  confidence  demands  that  financial  institutions, 
financial  markets,  and  payment  systems  remain  opera¬ 
tional  or  that  their  operations  can  be  quickly  restored. 

Additionally,  in  times  of  stress  the  Secretary  of  the 
T reasury,  the  C  hairman  of  the  Federal  Reserve,  and 
the  Securities  and  E  xchange  C  ommission  proactively 
address  public  confidence  issues,  as  was  done  following 
the  September  11  terrorist  attacks.  T  he  D  epartment  of 
theTreasury  and  federal  and  state  regulatory  commu¬ 
nities  have  developed  emergency  communications 
plans  for  the  banking  and  finance  sector. 

W  ith  regard  to  retail  financial  services,  physical  assets 
are  well  distributed  geographically  throughout  the 
industry.  T  he  sector’s  retail  niche  is  characterized  by  a 
high  degree  of  substitutability,  which  means  that  one 
type  of  payment  mechanism  or  asset  can  be  easily 
replaced  with  another  during  a  short-term  crisis. 

For  example,  in  retail  markets,  consumers  can  make 
payments  through  cash,  checks,  or  credit  cards. 

The  banking  and  financial  services  industry  is  highly 
regulated  and  highly  competitive.  Industry  profes¬ 
sionals  and  government  regulators  regularly  engage  in 
identifying  sector  vulnerabilities  and  take  appropriate 
protective  measures,  including  sanctions  for  institutions 
that  do  not  consistently  meet  standards. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  63 


Banking  and  F  inance  Sector  C  hallenges 

Like  the  other  critical  sectors,  the  banking  and 
financial  services  sector  relies  on  several  critical 
infrastructure  industries  for  continuity  of  operations, 
including  electric  power,  transportation,  and  public 
safety  services.  T  he  sector  also  specifically  relies  on 
computer  networks  and  telecommunications  systems  to 
assure  the  availability  of  its  services.  T  he  potential  for 
disruption  of  these  systems  is  an  important  concern. 

For  example,  the  equity  securities  markets  remained 
closed  for  four  business  days  following  September  11, 
not  because  any  markets  or  market  systems  were  inop¬ 
erable,  but  because  the  telecommunications  lines  in 
lower  M  anhattan  that  connect  key  market  participants 
were  heavily  damaged  and  could  not  be  restored  imme¬ 
diately.  As  a  mitigation  measure,  financial  institutions 
have  made  great  strides  to  build  redundancy  and 
backup  into  their  systems  and  operations. 

Overlapping  federal  intelligence  authorities  involved  in 
publicizing  threat  information  cause  confusion  and 
duplication  of  effort  for  both  industry  and  government. 
T  he  D  epartment  of  theT reasury  organized  the 
Financial  and  Banking  Information  Infrastructure 
Committee  (FBI  1C )  as  a  standing  committee  of  the 
PCIPB.TheFBIIC  comprises  representatives  from 
13  federal  and  state  financial  regulatory  agencies.1 
The  FBI  1C  is  currently  working  with  the  N  ational 
I  nfrastructure  Protection  C  enter,  the  F  inancial  Services 
ISAC  (FS-ISAC),  and  theO  FI  S  to  improve  the 
information  dissemination  and  sharing  processes. 

Banking  and  F  inance  Sector  I  nitiatives 

T  he  attacks  in  N  ew  York  C  ity  on  September  11 
showed  that  the  financial  services  industry  is  highly 
resilient.  T  he  strong  safeguards  and  back-up  systems 
the  industry  had  in  place  performed  well.  Since  1998, 
the  sector  has  been  working  with  the  D  epartment  of 
the  Treasury  to  organize  itself  to  address  the  risks  of 
the  emerging  threat  environment,  particularly  cyber 
intrusions.  It  was  also  the  first  sector  to  establish  an 
ISAC  to  share  security- related  information  among 
members  of  the  industry. 

M  ajor  institutions  in  this  sector  continue  to  perform 
ongoing  assessments  of  their  security  programs. 

After  the  September  11  attacks,  the  industry  and  its 


associations  initiated  lessons- 1  earned  reviews  to  identify 
corrective  actions  for  the  improvement  of  security  and 
response  and  recovery  programs,  as  well  as  to  provide  a 
forum  for  sharing  best  practices  through  their  trade 
associations  and  other  interdisciplinary  groups.  The 
sector  as  a  whole,  with  the  support  of  the  D  epartment 
of  theTreasury,  has  also  initiated  a  sector-wide  risk 
review.  I  n  addition  to  sector-wide  efforts,  individual 
institutions  have  stepped  up  their  investments  because 
of  their  better  understanding  of  the  threat. 

Additional  banking  and  finance  sector  protection 
initiatives  include  efforts  to: 

identify  and  address  the  risks  of  sector  dependencies  on 
electron icnetw  orks  and  telecommunications  services 

The  financial  services  sector’s  reliance  on  informa¬ 
tion  systems  and  networks  has  resulted  in  a  number 
of  concerns  for  the  industry.  T  he  D  epartment  of 
theTreasury,  in  concert  with  D  FI  S,  will  convene  a 
working  group  consisting  of  representatives  from 
the  telecommunications  and  financial  services 
sectors,  as  well  as  other  federal  agencies,  to  study 
and  address  the  risks  that  arise  from  the  sector's 
dependencies  on  electronic  networks  and 
tel  eco  m  m  u  n  i  cati  o  n  s  ser  vi  ces. 

E  nhance  the  exchange  of  securi  ty-  related  information 

D  FI  S  will  work  with  the  D  epartment  of  Treasury, 
the  FBIIC ,  and  the  FS-ISAC  to  improve  federal 
government  communications  with  sector  members 
and  streamline  the  mechanisms  through  which  they 
exchange  threat  information  on  a  daily  basis  as  well 
as  during  an  incident. 


1  TheFBIIC  includes  representatives  of  the  federal  and  state 
financial  regulatory  agencies,  including:  the  Commodity 
Futures  Trading  Commission,  theConference  of  State  Bank 
Supervisors,  the  Federal  Deposit  Insurance  Corporation,  the 
Federal  H  ousing  Finance  Board,  the  Federal  Reserve  Bank  of 
N  ew  York,  the  Federal  Reserve  Board,  the  N  ational 
Association  of  Insurance  Commissioners,  the  N  ational  Credit 
Union  Administration,  the  Office  of  the  Comptroller  of  the 
Currency,  the  Office  of  Federal  FI  ousing  E  nterprise 
Oversight,  the  Offices  of  H  omeland  and  Cyberspace 
Security,  the  Office  of  Thrift  Supervision,  and  the  Securities 
and  Exchange  Commission. 


64  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


CHEMICAL  INDUSTRY  AND  HAZARDOUS  MATERIALS 


T  he  chemical  sector  provides  products  that  are 
essential  to  the  U  .S.  economy  and  standard  of  living. 

T  he  industry  manufactures  products  that  are  funda¬ 
mental  elements  of  other  economic  sectors.  For 
example,  it  produces  fertilizer  for  agriculture,  chlorine 
for  water  purification,  and  polymers  that  create  plastics 
from  petroleum  for  innumerable  household  and  indus¬ 
trial  products.  Additionally,  more  than  $97  billion  of 
the  sector's  products  go  to  health  care  alone. 

C  urrently,  the  chemical  sector  is  the  N  ation’s  top 
exporter,  accounting  for  10  cents  out  of  every  dollar. 
The  industry  is  also  one  of  our  country’s  most  innova¬ 
tive.  It  earns  one  out  of  every  seven  patents  issued  in 
the  U.S.,  a  fact  that  enables  our  country  to  remain 
competitive  in  the  international  chemical  market. 

The  sector  itself  is  highly  diverse  in  terms  of  company 
sizes  and  geographic  dispersion.  Its  product  and 
service-delivery  system  depends  on  raw  materials, 
manufacturing  plants  and  processes,  and  distribution 
systems,  as  well  as  research  facilities  and  supporting 
infrastructure  services,  such  as  transportation  and 
electricity  products. 

Public  confidence  is  important  to  the  continued 
economic  robustness  and  operation  of  the  chemical 
industry.  U  ncertainty  regarding  the  safety  of  a  product 
impacts  producers  as  well  as  the  commercial  users  of 
the  product.  W  ith  respect  to  process  safety,  numerous 
federal  laws  and  regulations  exist  to  reduce  the  likeli¬ 
hood  of  accidents  that  could  result  in  harm  to  human 
health  or  the  environment.  H  owever,  there  is  currently 
no  clear,  unambiguous  legal  or  regulatory  authority  at 
the  federal  level  to  help  ensure  comprehensive,  uniform 
security  standards  for  chemical  facilities. 

I  n  addition  to  the  economic  consequences  of  a 
successful  attack  on  this  sector,  there  is  also  the  poten¬ 
tial  of  a  threat  to  public  health  and  safety.1  T  herefore, 
the  need  to  reduce  the  sector's  vulnerability  to  acts  of 
terrorism  is  important  to  safeguard  our  economy  and 
protect  our  citizens  and  the  environment. 

C  hemical  I  ndustry  and  H  azardous  M  aterials 
Sector  Challenges 

Assurance  of  supply  is  critical  to  downstream  users 
of  chemical  products  for  various  reasons.  M  any  large 
municipal  water  works  maintain  only  a  few  days 
supply  of  chlorine  for  disinfecting  their  water  supplies. 
Agricultural  chemicals,  particularly  fertilizers,  must  be 
applied  in  large  volumes  during  very  short  time  periods. 


Some  products  cannot  be  transferred  between  trans¬ 
portation  modes.  Facilities  with  "just-in-time"  delivery 
systems  maintain  fewer  and  smaller  chemical  stockpiles. 

The  industry’s  ability  to  protect  and  assure  the  quality 
of  its  own  chemical  stockpiles  is  also  important. 
Because  chemicals  are  vital  to  many  applications, 
contamination  of  key  chemical  stocks  could  impact  a 
wide  range  of  other  industries,  thereby  affecting  public 
health  and  the  economy.  I  n  addition  to  the  risk  of 
contamination  at  product  storage  facilities,  many 
chemicals  are  also  inherently  hazardous  and,  therefore, 
represent  potential  risks  to  public  health  and  safety  in  a 
malicious  context.  I  mproving  security  can  be  expensive, 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  65 


but  there  are  cost-effective  steps  that  industry  can 
take  to  reduce  vulnerabilities.  U  nfortunately,  the  risk 
profiles  of  chemical  plants  differ  tremendously  because 
of  differences  in  technologies,  product  mix,  design, 
and  processes.  T  herefore,  no  single,  specific  security 
regime  would  be  appropriate  or  effective  for  all 
chemical  facilities. 

M  any  current  statutes  related  to  the  handling  of  highly 
toxic  substances  were  created  decades  ago  and  may  no 
longer  be  effective  for  monitoring  and  controlling 
access  to  dangerous  substances.  For  example,  although 
licensed  distributors  of  pesticides  can  only  sell  them  to 
licensed  purchasers,  license  requests,  which  are  granted 
at  the  state  level  by  county  extension  agents,  are  fairly 
easy  to  obtain.  I  n  addition,  the  basis  for  licensing  varies 
from  state  to  state. 

As  in  most  other  industries,  the  chemical  industry 
relies  on  the  availability,  continuity,  and  quality  of 
service  and  supplies  from  other  critical  infrastructures. 
For  example,  the  chemical  industry  is  the  N  ation's 
third  largest  consumer  of  electricity.  An  assured  supply 
of  natural  gas  at  competitive  prices  is  another  crucial 
resource  for  the  sector. 

C  hemical  I  ndustry  and  H  azardous  M  aterials 
Sector  I  nitiatives 

C  urrently,  parts  of  the  industry  have  taken  positive, 
voluntary  steps  to  protect  sector  infrastructure.  For 
example,  several  trade  associations  have  developed  or 
are  developing  security  codes2  to  help  their  members 
address  the  need  to  reduce  vulnerabilities.  These 
commendable  efforts  will  make  important  contribu¬ 
tions  to  protecting  key  elements  of  the  chemical  and 
hazardous  materials  infrastructure  against  terrorist 
attack.  T  hese  efforts  are  in  the  early  stages  of 
implementation.  FI  owever,  it  should  be  also  noted  that 
a  significant  percentage  of  companies  that  operate 
major  hazardous  chemical  facilities  do  not  abide  by 
voluntary  security  codes  developed  by  other  parts  of 
the  industry. 


C  hemicals  and  hazardous  materials  sector  protection 
initiatives  include  efforts  to: 

P  romote  enhanced  site  security 

D  FI  S,  in  concert  with  E  PA ,  will  work  with 
Congress  to  enact  legislation  that  would  require 
certain  chemical  facilities,  particularly  those  that 
maintain  large  quantities  of  hazardous  chemicals  in 
close  proximity  to  population  centers,  to  undertake 
vulnerability  assessments  and  take  reasonable  steps 
to  reduce  the  vulnerabilities  identified. 

R  eview  current  law  sand  regulationsthat  pertain  to  the 
sale  and  distribution  ofpestiddesand  other  highly  toxic 
substances 

E  PA ,  in  consultation  with  D  FI  S  and  other  federal, 
state,  and  local  agencies,  as  well  as  with  other 
appropriate  stakeholders,  will  review  current  prac¬ 
tices  and  existing  statutory  requirements  on  the 
distribution  and  sale  of  highly  toxic  pesticides  and 
industrial  chemicals.  This  process  will  help  identify 
whether  additional  measures  may  be  necessary  to 
address  security  issues  related  to  those  substances. 

C  ontinue  to  develop  the  chemical  I SA  C  and  recruit  sector 
constituents  to  partidpate 

The  purpose  of  the  chemical  sector's  I  SAC,  which 
is  in  the  early  stages  of  development,  is  to  facilitate 
advanced  warnings  on  security  threats  and  the 
sharing  of  other  security- related  data.  D  FI  S  and 
EPA,  in  concert  with  chemical  industry  officials, 
will  promote  the  I  SAC  concept  within  the  sector 
in  order  to  draw  increased  participation  from  the 
industry  at  large. 


1  Specific  chemical  and  hazardous  materials  facilities  may  fall 
within  the  definitional  context  of  "key  assets,"  however,  their 
specific  protection  issues  relate  directly  to  the  entire  sector 
and  are  therefore  discussed  in  this  chapter. 

2  For  example,  the  A  merican  C  hemistry  C  ouncil's  Responsible 
Care® Security  Code  of  M  anagement  Practices. 


66  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


POSTAL  AND  SHIPPING 


Americans  depend  heavily  on  the  postal  and  shipping 
sector.  E  ach  day,  we  place  more  than  two- thirds  of  a 
billion  pieces  of  mail  into  the  U.S.  postal  system;  and 
each  day  more  than  300,000  city  and  rural  postal 
carriers  deliver  that  mail  to  more  than  137  million 
delivery  addresses  nationwide.  In  all,  the  vast  network 
operated  by  the  United  States  Postal  Service  (USPS) 
consists  of  a  headquarters  in  Washington,  D  .C .,  tens  of 
thousands  of  postal  facilities  nationwide,  and  hundreds 
of  thousands  of  official  drop- box  locations.  USPS 
employs  more  than  749,000  full-time  personnel  in 
rural  and  urban  locations  across  the  country  and 
generates  more  than  $60  billion  in  revenues  each  year. 
Together,  USPS  and  private- industry  mailing  and 
shipping  revenues  exceed  $200  billion  annually. 

T  he  postal  system  is  highly  dependent  on  and 
interconnected  with  other  key  infrastructure  systems, 
especially  the  transportation  system.  USPS  depends  on 
a  transportation  fleet  composed  of  both  service-owned 
and  contactor- operated  vehicles  and  equipment.  M  ail 
also  travels  daily  by  commercial  aircraft,  truck,  railroad, 


and  ship.  Because  of  these  dependencies,  many  key 
postal  facilities  are  collocated  with  other  transportation 
modalities  at  various  points  across  the  U  nited  States. 

T  he  expansiveness  of  the  national  postal  facilities 
network  presents  a  significant,  direct  protection  chal¬ 
lenge.  Additionally,  the  size  and  pervasiveness  of  the 
system  as  a  whole  have  important  implications  in  terms 
of  the  potential  secondary  effects  of  a  malicious  attack. 
The  Fall  2001  anthrax  attacks  underscore  this  concern. 
In  addition  to  localized  mail  stoppages  across  the  U.S. , 
the  tainted  mail  caused  widespread  anxiety  that 
translated  into  significant  economic  impact. 

H  istorically,  the  American  public  has  placed  great  trust, 
confidence,  and  reliance  on  the  integrity  of  the  postal 
sector.  This  trust  and  confidence  are  at  risk  when  the 
public  considers  the  mail  service  to  be  a  potential  threat 
to  its  health  and  safety.  Consequently,  USPS  continues 
to  focus  on  the  specific  protection  issues  facing  its 
sector  and  is  working  diligently  to  find  appropriate 
solutions  to  increase  postal  security  without  hampering 
its  ability  to  provide  fast,  reliable  mail  service. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  67 


Postal  and  Shipping  Sector  C  hallenges 

The  protection  challenges  and  initiatives  discussed  in 
this  section  relate  specifically  to  the  efforts  undertaken 
by  USPS.  Commercial  postal  and  shipping  companies 
are  in  the  process  of  organizing  themselves  as  a  sector 
to  identify  and  address  specific  protection  issues  within 
their  industry.  W  hile  the  USPS  has  worked  with  many 
of  these  companies  to  address  critical  infrastructure 
protection  issues,  there  is  further  work  to  be  done  in 
thisarea.  Assisted  by  USPS,  DH  S  will  engage  the 
industry’s  major  players  in  an  effective  dialogue  to 
address  critical  infrastructure  protection  issues  that 
cross  the  entire  sector. 

USPS  has  identified  five  areas  of  concern  for  the  postal 
system: 

•  Points  of  entry  and  locations  of  key  facilities; 

•  The  mail's  chain  of  custody; 

•  U  nique  constitutional  and  legal  issues; 

•  Interagency  coordination;  and 

•  The  ability  to  respond  in  emergency  situations. 

T  he  fact  that  there  are  numerous  points  of  entry  into 
the  postal  system  complicates  its  protection. 

C  ompounding  this  problem  is  the  fact  that  these  access 
points  are  geographically  dispersed,  including  the 
multitude  of  postal  drop  boxes  nationwide.  E  ffective, 
affordable  technology  to  scan  mail  and  provide  early 
warning  of  potential  hazards  is  under  current  evaluation. 

T  he  location  of  many  key  postal  service  facilities  can 
also  aggravate  risk- management  challenges.  Several 
major  USPS  facilities  are  collocated  with  or  adjacent  to 
other  government  agencies  or  major  transportation 
hubs.  Relocating  these  facilities  to  mitigate  risk  is  often 
constrained  by  limited  resources,  a  lack  of  available, 
alternative  sites,  and  other  pressing  local  imperatives. 

A  nother  factor  affecting  postal  security  is  the  fact  that 
USPS  does  not  always  maintain  control  of  the  mail 
during  its  entire  chain  of  custody.  Oftentimes,  inde¬ 
pendent  contractors  transport  mail  for  U  SPS.  Because 
USPS  utilizes  hundreds  of  long-haul  mail  carriers,  mail 
moves  into  and  out  of  USPS  control  along  its  route. 

To  address  this  issue,  USPS  transportation  purchasing 
requirements  call  for  all  transportation  vendors,  their 
employees,  and  subcontractors  to  submit  to  criminal 
and  drug  background  checks.  T  hese  checks  include 
fingerprinting  and  follow-up  if  necessary  by  the  Postal 
Inspection  Service. 

USPS  security  efforts  face  constitutional  and  legal 
challenges  that  are  unique  to  the  postal  and  shipping 


sector.  Specifically,  the  Fourth-Amendment  prohibition 
of  unreasonable  search  and  seizure  and  the  sanctity  of 
the  postal  seal  make  it  necessary  to  justify  the  scanning 
or  x-ray  of  a  parcel  for  hazardous  materials.  Regardless, 
some  technology  vendors  resist  developing  or 
marketing  advanced  sensing  equipment  out  of  concern 
that  they  would  be  held  liable  if  their  device  failed  to 
detect  an  actual  threat.  T  he  Support  Anti-  terrorism  by 
Fostering  EffectiveT  echnologies(SAF  ETY)  Act,  enacted 
as  part  of  the  FI  omeland  Security  Act  of  2002,  reduces 
these  risks  by  providing  strong  product  liability 
protection  for  manufacturers  of  anti -terrorism  devices. 

E  nsuring  that  USPS  is  able  to  respond  effectively  in 
emergency  situations  is  another  challenge  for  the 
sector.  W  hile  USPS  has  worked  extensively  with 
vendors  and  the  W  hite  H  ouse  0  ffice  of  Science  and 
T echnology  Policy  to  develop  solutions,  currently  there 
is  no  recognized  set  of  standards  to  guide  USPS  and 
the  private  shipping  industry  in  evaluating  products 
for  detecting,  decontaminating,  and  remediating  the 
effects  of  certain  hazards.  Furthermore,  there  are 
inadequate  stockpiles  of  equipment  and  materials  to 
enable  sustained  response  activities.  For  instance, 
the  supply  of  chemicals  used  to  decontaminate  facilities 
affected  by  the  Fall  2001  anthrax  incidents  depended 
on  a  few  companies,  each  of  which  produces  only  one 
of  the  compound's  constituent  parts. 

I n  responding  to  the  anthrax  incidents,  USPS  worked 
with  various  federal  agencies  and  state  and  local 
governments  and  continues  to  coordinate  and  plan 
with  these  groups.  Further  coordination  and  planning 
will  be  necessary  to  ensure  that  protection  measures 
developed  are  effective  across  the  entire  sector.  T  he 
federal  authority  to  implement  certain  protective  and 
response  measures  related  to  the  actual  or  potential 
transmission  of  certain  biological  agents  across  state 
lines  is  not  widely  understood.  Resolving  these  ambi¬ 
guities  in  advance  of  a  crisis  situation  would  contribute 
greatly  to  the  coordination  of  protection  and 
emergency  response  efforts. 

Postal  and  Shipping  Sector  I  nitiatives 

D  FI  S  will  work  with  private  shipping  and  mail  firms 
to  enable  them  to  incorporate  their  protection  issues 
into  a  more  comprehensive  approach  to  critical 
infrastructure  protection  for  this  sector. 

Additionally,  the  USPS  has  outlined  six  core  initiatives 
in  its  emergency  preparedness  plans:  prevention; 
protection  and  health-risk  reduction;  detection  and 
identification;  intervention;  decontamination;  and 
investigation.  Specific  key  action  areas  that  support 
these  initiatives  include  efforts  to: 


68  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


Improve  protection  and  responsecapabilities 

D  H  S  and  USPS  will  conduct  planning  to  increase 
reserve  stockpiles  of  equipment  and  materials 
needed  for  emergency- incident  response,  particu¬ 
larly  for  C B R  contaminants. They  will  also  review 
requirements  for  manufacturing  surge  capacity  for 
certain  materials. 

D  H  S  and  USPS  will  also  work  with  other  federal 
agencies  and  state  and  local  authorities  to  facilitate 
coordinated  planning  efforts  to  develop  and  imple¬ 
ment  risk  avoidance  and  reduction  measures,  as  well 
as  to  establish  common  protocols  for  incident 
response  and  remediation. 

A  ssure  security  of  international  mail 

D  H  S  and  U  SPS  will  work  with  other  appropriate 
agencies  to  clarify  and  formalize  responsibilities  for 
assuring  the  security  of  mail  transiting  U  .S.  borders, 
both  inbound  and  outbound  (e.g.,  between  the 
USPS  and  U.S.  C ustoms Service). 

Promoteand  support  I  SAC  partidpation 

D  H  S  will  promote  the  postal  and  shipping  sector’s 
participation  within  an  appropriate  information 
sharing  structure.  This  structure  must  include  key 
government-  and  private- sector  stakeholders 
involved  with  the  delivery  of  air  and  ground  mail, 
private  parcels,  and  heavy  cargo. 


C  onduct  enhanced  risk  analyses  of  key  fad li  ties 

DH  S,  USPS,  and  U.S.  Postal  Inspection  Service 
will  conduct  assessments  of  postal  facilities  that  are 
collocated  with  other  high-risk  facilities  requiring 
more  thorough  risk  analyses.  T  hese  more  rigorous 
assessments,  which  must  take  into  account  terrorist 
capabilities  and  motivations  and  facility  vulnerabili¬ 
ties,  will  provide  both  indications  and  justification 
for  the  relocation  of  high-risk  USPS  facilities. 

Improve  customer  identification  and  correlation  with 
their  mail 

USPS  will  implement  customer  identification  and 
correlation  mechanisms  at  designated  mail  intake 
points  and  improve  passive,  nonintrusive  parcel 
inspections  for  the  detection  of  hazardous  material. 

I  dentify  conflicts  with  respect  to  coordinated 
multi- jurisdictional  responses 

D  H  S,  USPS,  and  D OJ  will  work  together  with 
state  and  local  governments  to  identify  and  address 
conflicts  in  federal,  state,  and  local  laws  and  regula¬ 
tions  that  impair  the  abilities  of  multi-jurisdictional 
entities,  like  the  USPS,  to  respond  effectively  in 
emergency  situations. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  69 


70  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


PROTECTING  KEY  ASSETS 


Key  assets  represent  a  broad 
array  of  unique  facilities,  sites, 
and  structures  whose  disrup¬ 
tion  or  destruction  could  have 
significant  consequences 
across  multiple  dimensions. 

0  ne  category  of  key  assets 
comprises  the  diverse  array  of 
national  monuments,  symbols, 
and  icons  that  represent  our 
N  ation’s  heritage,  traditions 
and  values,  and  political 
power.  T  hey  include  a  wide 
variety  of  sites  and  structures, 
such  as  prominent  historical 
attractions,  monuments, 
cultural  icons,  and  centers  of 
government  and  commerce. 

T  he  sites  and  structures  that 
make  up  this  key  asset  cate¬ 
gory  typically  draw  large 
amounts  of  tourism  and 
frequent  media  attention- 
factors  that  impose  additional 
protection  challenges. 

A  nother  category  of  key  assets 
includes  facilities  and  struc¬ 
tures  that  represent  our 
national  economic  power  and 
technological  advancement. 

M  any  of  them  house  signifi¬ 
cant  amounts  of  hazardous 
materials,  fuels,  and  chemical 
catalysts  that  enable  important 
production  and  processing 
functions.  D  isruption  of  these 
facilities  could  have  significant 
impact  on  public  health  and 
safety,  public  confidence,  and 
the  economy. 


A  third  category  of  key  assets  includes  such  structures 
as  prominent  commercial  centers,  office  buildings,  and 
sports  stadiums,  where  large  numbers  of  people 
regularly  congregate  to  conduct  business  or  personal 
transactions,  shop,  or  enjoy  a  recreational  pastime. 


G  iven  the  national -level  fame  of  these  sites  and 
facilities  and  the  potential  human  consequences  that 
could  result  from  their  attack,  protecting  them  is 
important  in  terms  of  both  preventing  fatalities  and 
preserving  public  confidence. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  71 


NATIONAL  MONUMENTS  AND  ICONS 


N  ational  M  onument  and  I  con  C  hallenges 

0  ur  national  monuments  and  icons  present  specific 
challenges  because  their  protection  typically  combines 
the  authorities,  responsibilities,  and  resources  of  federal, 
state,  and  local  jurisdictions,  and,  in  some  cases,  private 
foundations.  A  clear  division  of  labor,  resources,  and 
accountability  is  often  difficult  to  distinguish. 

The  need  to  protect  our  national  icons  and  monuments 
from  terrorist  attack  requires  the  development  and 
coordination  of  comprehensive  policies,  practices,  and 
protective  measures.  W  e  are  also  faced  with  the  task  of 
balancing  open  visitor  access  to  these  structures  with 
the  protection  of  visitors  and  the  structures  themselves. 
M  ost  often  their  protection  entails  restricting  public 
access  to  certain  areas  and  curtailing,  or  even 
prohibiting,  the  assembly  of  large  numbers  of  visitors. 

T  he  D  epartment  of  the  I  nterior  (D  0 1 )  is  the  lead 
federal  department  with  primaryjurisdiction  over 
national  icons  and  monuments.  It  has  diverse 
responsibilities,  including  the  protection  of  a  number 
of  potential  targets.  Such  protection  is  particularly 
important  in  the  case  of  icons  and  symbols  that  figure 
prominently  in  national  celebrations  and  events. 


Accordingly,  D  0  I  must  coordinate  with  law 
enforcement  agencies  across  jurisdictions  and  entities 
directly  responsible  for  intelligence  gathering  and 
homeland  security. 

D  0 1  and  its  state,  local,  and  private  sector  counterparts 
also  face  unique  challenges  with  respect  to  recruiting, 
training,  and  retaining  a  robust  security  force. 

G  iven  the  need  for  the  physical  protection  of  such 
a  wide  array  of  potential  targets  (e.g.,  national  parks, 
monuments,  and  historic  buildings),  maintaining  a 
highly  trained  security  force  is  a  priority. 

N  ational  M  onument  and  I  con  I  nitiatives 

T o  address  the  challenges  associated  with  the 
protection  of  our  national  monuments  and  icons, 
we  will  take  action  in  the  following  areas: 

D  efine  criticality  criteria  for  national  monuments*  icons, 
and  symbols 

D  0 1  will  work  in  concert  with  D  H  S  to  develop 
specific  guidance  to  define  criteria  and  standards  for 
determining  the  criticalities  and  protection  priorities 
for  our  national  monuments,  icons,  and  symbols. 


72  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


C  ondud  threat  and  vulnerability  assessments 

D  0 1  will  work  in  concert  with  D  H  S  and  other 
appropriate  authorities  to  conduct  threat  and 
vulnerability  assessments  to  identify  gaps  in  visitor 
protection  processes  as  well  as  asset  protection. 

R  etain  a  quality  security  force 

D  0 1  will  explore  alternatives  to  foster  efforts  to 
recruit,  train,  and  retain  a  skilled  and  motivated 
security  force. 

C  ondud  security-  focused  public  outreach  and  awareness 
programs 

D  0 1  will  enlist  public  support  in  the  protection  of 
our  national  icons  and  symbols  through  sustained 
public  outreach  and  awareness  programs. 

C  ollaborate  with  stateand  local  governments  and  private 
foundations  to  assure  the  protedion  of  symbols  and  icons 
outsi de  the  federal  domai n 

D  0 1  will  work  with  state  and  local  governments 
and  private  institutions  to  explore  alternatives  to 
protect  symbols  and  icons  such  as  historical 
buildings  and  landmarks  that  are  outside  the 
purview  of  the  federal  government. 

E  valuate  innovative  technologies 

D  0 1 ,  in  concert  with  D  H  S  and  other  key 
stakeholders,  will  explore  ways  to  employ  security 
technologies  to  ensure  the  protection  of  visitors 
to  monuments  and  other  like  attractions. 

M  ake  provisions  for  extra  security  during  high-  profile 
events 

D  0 1  will  work  with  law  enforcement  agencies  to 
manage  visitor  periods  at  national  monuments  and 
provide  extra  security  during  high-profile  events 
taking  place  in  or  around  national  icons. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  73 


NUCLEAR  POWER  PLANTS 


N  uclear  power  represents  about  20  percent  of  our 
N  ation's  electrical  generation  capacity.  T  he  U .S.  has  104 
commercial  nuclear  reactors  in  31  states.  For  25  years, 
federal  regulations  have  required  that  these  facilities 
maintain  rigorous  security  programs  to  withstand  an 
attack  of  specified  adversary  strength  and  capability. 

N  uclear  power  plants  are  also  among  the  most  physi¬ 
cally  hardened  structures  in  the  country  designed  to 
withstand  extreme  events  such  as  hurricanes,  tornadoes, 
and  earthquakes. Their  reinforced  engineering  design 
provides  inherent  protection  through  such  features  as 
robust  containment  buildings,  redundant  safety  systems, 
and  sheltered  spent  fuel  storage  facilities. 

T  he  security  at  nuclear  power  plants  has  been  enhanced 
significantly  in  the  aftermath  of  the  September  11 
attacks.  All  plants  remain  at  heightened  states  of 
readiness,  and  specific  measures  have  been  implemented 
to  enhance  physical  security  and  to  prevent  and  miti¬ 
gate  the  effects  of  a  deliberate  release  of  radioactive 


materials.  Steps  have  been  taken  to  enhance 
surveillance,  provide  for  more  restricted  site  access, 
and  improve  coordination  with  law  enforcement  and 
military  authorities.  I  n  addition  to  these  augmented 
security  measures,  all  nuclear  power  plants  have  robust 
security  and  emergency  response  plans  in  place  to 
further  assure  public  health  and  safety  in  the  unlikely 
event  of  a  malicious  act  and/or  radioactive  release. 

N  uclear  Power  Plant  C  hallenges 

L  osing  the  capabilities  of  a  single  nuclear  power  plant 
may  have  only  a  minor  impact  on  overall  electricity 
delivery  within  the  context  of  our  robust  national 
power  grid.  N  evertheless,  a  terrorist  attack  on  any 
nuclear  facility  would  be  considered  a  significant 
security  event.  I  n  an  unlikely  worst-case  scenario, 
a  successful  terrorist  strike  against  a  nuclear  facility 
could  result  in  a  release  of  radioactive  material.  Even 
if  radioactive  material  were  not  released,  widely  held 
misconceptions  of  the  potential  consequences  of  an 


74  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


attack  on  a  nuclear  facility  could  have  significant 
negative  impact. 

N  RC  is  currently  performing  a  detailed  design  basis 
threat  and  vulnerability  analysis  for  nuclear  power 
plants  to  help  identify  additional  security  enhance¬ 
ments  that  may  be  warranted.  Additional  prudent 
measures  should  be  examined  to  help  strengthen  the 
defensive  posture  of  these  facilities. 

N  uclear  Power  Plant  I nitiatives 

To  overcome  protection  challenges,  we  will: 

C  oordinate  efforts  to  perform  standardized  vulnerability 
and  risk  assessments 

N  RC  and  D  H  S  will  work  with  owners  and 
operators  of  nuclear  power  plants  to  develop  a 
standard  methodology  for  conducting  vulnerability 
and  risk  assessments. 

E  stablish  common  processesand  identify  resources  needed 
to  augment  security  at  nudear  power  plants 

The  N  RC  and  D  H  S  will  work  in  concert  with  plant 
owners  and  operators  and  appropriate  local,  state, 
and  federal  authorities  to  develop  a  standard  process 
for  requesting  external  security  augmentation  at 
nuclear  power  plants  during  heightened  periods  of 
alert  and  in  the  event  of  an  imminent  threat. 

C  riminalizethe  carrying  of  unauthorized  weapons  or 
explosives  into  nudear  fad  I  i  ties 

N  RC ,  in  coordination  with  D  H  S,  will  pursue 
legislation  to  make  the  act  of  carrying  an  unautho¬ 
rized  weapon  or  explosive  into  a  nuclear  power 
plant  a  federal  crime. 

E  nhance  the  capabilities  of  nudear  power  plant 
security  forces 

N  RC ,  in  coordination  with  D  H  S,  will  pursue 
legislation  authorizing  security  guards  at  licensed 
facilities  to  carry  and  use  more  powerful  weapons.  It 
will  also  assist  the  industry  to  develop  standards  and 


implement  additional  training  in  counter-terrorist 
techniques  for  private  security  forces. 

Seek  legislation  to  apply  sabotage  law  sto  nudear  fadlities 

N  RC ,  in  coordination  with  D  H  S,  will  pursue 
legislation  to  make  federal  prohibitions  on  sabotage 
applicable  to  nuclear  facilities  and  their  operations. 

E  nhance  public  outreach  and  awareness 

N  RC  and  D  H  S  will  work  with  plant  owners  and 
operators  and  appropriate  local  and  state  authorities 
to  enhance  public  outreach  and  awareness  programs 
and  emergency  preparedness  programs. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  75 


DAMS 


Some  of  our  larger  and  more  symbolic  dams  are  major 
components  of  other  critical  infrastructure  systems 
that  provide  water  and  electricity  to  large  populations, 
cities,  and  agricultural  complexes.  T  here  are  approxi¬ 
mately  80,000  dam  facilities  identified  in  the  N  ational 
Inventory  of  D  ams.  M  ost  are  small,  and  their  failure 
would  not  result  in  significant  property  damage  or  loss 
of  life.  The  federal  government  is  responsible  for 
roughly  10  percent  of  the  dams  whose  failure  could 
cause  significant  property  damage  or  have  public 
health  and  safety  consequences.  T  he  remaining  critical 
dams  belong  to  state  or  local  governments,  utilities, 
and  corporate  or  private  owners. 

D  am  C  hallenges 

U  nder  current  policies  and  laws,  dam  owners  are 
largely  responsible  for  the  safety  and  security  of  their 
own  structures.  H  ence,  the  resources  available  to 
protect  dam  property  vary  greatly  from  one  category  to 
the  next.  Additionally,  the  distributed  nature  of  dam 
ownership  also  complicates  assessment  of  the  potential 
consequences  of  dam  failure  for  certain  categories  of 
dams.  G  iven  these  realities,  the  need  to  develop  more 
comprehensive  mechanisms  for  assessing  and 
managing  risks  to  dams  is  clear. 


Dam  Initiatives 

T o  overcome  protective  challenges  for  dam  structures, 

we  will  take  action  to: 

D  evelop  risk  assessment  methodologies  for  dams 

D  H  S,  in  cooperation  appropriate  federal,  state,  and 
local  government  representatives  and  private- sector 
dam  owners  will  design  risk  assessment  methodolo¬ 
gies  for  dams  and  develop  criteria  to  prioritize  the 
dams  in  the  N  ational  I  nventory  to  identify 
structures  requiring  enhanced  security  evaluations 
and  protection  focus. 

D  evelop  protective  action  plans 

D  H  S,  together  with  other  appropriate  departments 
and  agencies,  will  establish  an  intergovernmental 
working  group  to  explore  appropriate  protective 
actions  for  the  N  ation’s  critical  dams. 

E  stablish  a  sector  ■  I SA  C 

D  H  S  will  work  with  other  appropriate  public  and 
private  sector  entities  to  establish  an  information 
and  warning  structure  for  dams  similar  to  the  I  SAC 
model  in  use  within  other  critical  infrastructure 
sectors. 

Institute  a  national  dam  security  program 

D  H  S  and  other  appropriate  departments  and 
agencies,  such  as  the  A  ssociation  of  State  D  am 
Safety  Officials  and  U  nited  States  Society  of  D  ams, 
will  collaborate  to  establish  a  nationwide  security 
program  for  dams. 

D  evelop  emergency  action  plans 

D  H  S,  together  with  other  appropriate  departments 
and  agencies,  will  identify  the  areas  downstream 
from  critical  dams  that  could  be  affected  by  dam 
failure  and  develop  appropriate  population  and  infra¬ 
structure  protection  and  emergency  action  plans. 

D  evelop  technology  to  provide  protective  solutions 

D  H  S,  together  with  other  appropriate  departments 
and  agencies,  will  explore  new  protective  technology 
solutions  for  dams.  T echnology  solutions  hold 
significant  promise  for  the  identification  and  miti¬ 
gation  of  waterborne  threats.  For  example,  technical 
options  might  include  deploying  sensors,  barriers 
and  communications  systems  to  reduce  the  possi¬ 
bility  of  an  unauthorized  craft  or  device  entering  a 
critical  zone  located  near  a  navigational  dam. 


76  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


GOVERNMENT  FACILITIES 


G  overnment  Facilities  I  nitiatives 

T o  overcome  protection  challenges  associated  with 
government  facilities,  we  will: 


Before  the  September  11  attacks,  the  principal  threat 
to  government  buildings  was  the  use  of  explosives. 
After  the  1995  bombing  of  the  Alfred  P.  M  urrah 
Building  in  0  klahoma  C  ity,  the  operators  of  many 
large  government  centers  across  the  country  imple¬ 
mented  enhanced  measures,  such  as  concrete  barriers, 
intensified  surveillance,  and  parking  restrictions,  to 
safeguard  key  physical  assets.  W  hile  explosives  remain 
an  important  concern,  the  innovative,  highly  coordi¬ 
nated  A  l-Q  aeda  attacks  have  added  new  dimensions  to 
the  threats  now  facing  U.S.  government  facilities. 

The  General  Services  Administration  (GSA)  is  a 
principal  agency  responsible  for  the  management  of 
federal  government  facilities.  Additional  departments 
and  agencies  are  similarly  involved  in  the  management 
of  federally  owned  or  operated  facilities,  including  D  oD 
and  the  D  epartment  of  Veterans  Affairs.  W  ithin  the 
overall  federal  inventory  are  buildings  that  the  federal 
government  owns  and  others  that  it  leases  from  the 
private  sector.  G  SA  works  with  other  federal  agencies  to 
conduct  facility  security  assessments  to  ensure  that  each 
facility  owned  or  leased  by  G  SA  identifies  vulnerabilities 
to  specific  types  of  threats.  T  he  Federal  Protective 
Service,  which  will  transition  into  D  H  S,  works  with 
government  tenants  and  private- sector  owners  to 
identify  credible  threats  and  implement  appropriate 
countermeasures  to  provide  cost-effective  security. 

G  overnment  Facilities  C  hallenges 

M  ost  government  organizations  occupy  buildings  that 
are  also  used  by  a  variety  of  nongovernmental  tenants, 
such  as  shops  and  restaurants  where  the  public  is  able  to 
move  about  freely.  I  n  federally  owned  buildings,  federal 
laws  and  regulations  apply.  In  private  facilities  with 
federal  tenants,  federal  laws  and  regulations  only  apply 
in  areas  that  are  federally  occupied.  For  instance,  federal 
laws  and  regulations  prohibit  the  entry  into  federal 
buildings  of  prohibited  weapons.  In  buildings  where 
the  federal  government  leases  space,  the  weapons  ban  is 
applicable  only  to  those  spaces  occupied  by  the  federal 
tenants.  Private  owners  of  these  properties  may  not  want 
or  have  the  ability  to  modify  their  procedures  to  accom¬ 
modate  the  increased  or  special  security  countermeasures 
required  by  their  federal  tenants,  such  as  installing 
surveillance  cameras  in  lobbies,  redesigning  entry  points 
to  restrict  the  flow  of  traffic,  or  setting  up  x-ray  machines 
and  metal  detectors  at  entrances.  T  he  need  to  consider 
the  delicate  balance  between  security  and  the  public’s 
right  to  privacy  presents  additional  challenges. 


D  eve/op  a  process  to  screen  nonfederal  tenantsand 
visitorsentering  private  sector  fadlities  that  house 
federal  organizations 

D  FI  S,  together  with  G  SA  and  other  federal 
departments  and  agencies,  will  work  with  real-estate 
associations  in  the  private  sector  to  implement  a 
noninvasive  screening  process  at  facilities  that  house 
private  businesses  as  well  as  federal  organizations. 

D  eterminethecriticality  and  vulnerability  of 
government  fadlities 

D  FI  S,  together  with  G  SA  and  other  federal 
departments  and  agencies,  will  work  with  owners 
of  federally  occupied  facilities  to  establish  a  standard 
methodology  to  determine  a  government  facility’s 
criticality  and  vulnerability  to  facilitate  security- 
related  planning. 

D  evefop  long-  term  construction  standards  for  fadlities 
requiring  sped ali zed  security  measures 

N  I  ST,  together  with  D  FI  S  and  other  federal 
government  departments  and  agencies,  will  continue 
current  efforts  to  develop  long-term  construction 
design  standards  for  facilities  requiring  blast 
resistance  or  other  specialized  security  measures. 

I  mplementnew  technological  security  measures  at  federally 
occupied  fadlities 

D  FI  S,  together  with  G  SA  and  other  federal 
departments  and  agencies,  will  work  with  owners  of 
federally  occupied  facilities  to  explore  measures  to 
enhance  security  measures  in  the  common  areas  of 
federally  occupied  facilities  (e.g.,  sensor  systems  in 
lieu  of  manual-access  control). 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  77 


COMMERCIAL  KEY  ASSETS 


Protecting  prominent  commercial  centers,  office 
buildings,  sports  stadiums,  theme  parks,  and  other  sites 
where  large  numbers  of  people  congregate  to  pursue 
business  activities,  conduct  personal  commercial 
transactions,  or  enjoy  recreational  pastimes  presents 
significant  challenges.  D  ay-to-day  protection  of  such 
facilities  is  the  responsibility  of  their  commercial 
owners  and  operators,  in  close  cooperation  with  local 
law  enforcement. 

T  he  federal  government's  responsibility  for  the 
protection  of  these  assets  is  more  or  less  indirect.  Its 
activities  include  providing  timely  threat  indications 
and  warnings  and  working  with  commercial  enterprises 
to  harmonize  individual  facility  security  processes  with 
the  various  H  omeland  Security  Advisory  System  levels 
of  alert.  Additionally,  providing  support  and  input  to 
organizations  that  develop  standards  and  guidance  for 
building  construction  and  facility  heating,  ventilating, 
and  air  conditioning  (H  VAC )  systems  constitutes  an 
important  federal  government  activity. 

T  he  federal  government  typically  coordinates  or 
provides  physical  security  at  commercial  facilities  only 
in  conjunction  with  dignitary  visits  or  designated 


N  ational  Security  Special  Events.  G  iven  the 
national- level  visibility  and  potential  human  and 
economic  consequences  of  prominent  commercial  sites 
and  facilities,  it  is  important  for  the  government  and 
commercial  sectors  to  work  together  to  assure  the 
protection  of  our  nation’s  prominent  business  centers 
and  gathering  places. 

Commercial  KeyAssetC hallenges 

The  likelihood  of  terrorists  targeting  and  attacking  any 
specific,  prominent  commercial  facility  or  activity  is 
difficult  to  determine.  Potential  terrorist  attack 
methods  range  from  conventional  explosives  to  C  BR 
weapons  of  mass  destruction.  Each  facility’s  vulnera¬ 
bility  to  the  various  means  by  which  terrorists  could 
strike  is  unique  as  determined  by  its  engineering 
design,  size,  age,  purpose,  and  number  of  inhabitants. 
Standards  for  building  design,  construction,  and  secu¬ 
rity  also  vary  widely  across  enterprises,  industrial 
sectors,  and  governmental  jurisdictions.  For  the  most 
part,  commercial  owners  and  operators  must  be 
responsible  for  assessing  and  mitigating  their  specific 
facility  vulnerabilities  and  practicing  prudent  risk 
management  and  mitigating  measures. 


78  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


C  ommercial  Key  A  sset  I  nitiatives 

There  are  no  specific  actions  that  will  eliminate  all  of 
the  potential  risks  associated  with  the  threat  of  a  deter¬ 
mined  terrorist  attack  on  a  prominent  commercial 
facility  or  activity.  H  owever,  there  are  certain  steps  that 
can  be  taken  to  reduce  a  facility’s  attractiveness  as  a 
target  by  complicating  attack  planning  and  execution, 
and  helping  to  mitigate  the  effects  of  an  explosive 
attack  or  C  BR  release. 

For  example,  reducing  a  commercial  facility’s 
vulnerability  to  a  high  explosive  or  C  BR  attack 
requires  a  comprehensive  approach.  T  he  first  step  is  to 
integrate  considerations  for  potential  threats  into  the 
engineering  design  of  the  facility  and  its  supporting 
systems  (e.g.,  H  VAC  systems). 

T  he  second  step  is  a  thorough  assessment  of 
physical-security  design  features,  systems,  processes, 
and  procedures  that  serve  to  deny  or  limit  terrorist 
access  to  a  facility  and  its  key  nodes.  Preventing 
terrorist  access  to  a  targeted  facility  requires  adequate 
physical  security  for  all  entrances,  storage  areas,  main¬ 
tenance  areas,  and  rooftops,  as  well  as  securing  access 
to  the  outdoor  air  intakes  of  facility  H  VAC  systems. 

T  he  third  step  is  an  interior  assessment  of  H  VAC 
systems  and  their  components.  Specifically,  this 
measure  focuses  on  their  vulnerability  as  conduits  for 
the  introduction  and  dispersal  of  C  BR  agents.  Key 
areas  considered  during  this  assessment  include  H  VAC 
system  controls,  airflow  patterns,  overpressure,  purge 
capability,  filtering  efficiency,  and  leakage  potential.  If 
designed,  installed,  and  maintained  properly,  air  filtra¬ 
tion  and  cleaning  systems  can  mitigate  the  effects  of 
C  BR  agents  by  removing  contaminants  from  a  facility’s 
ai  rborne  environment. 

A  final  step  involves  developing  and  rehearsing  facility 
contingency  plans  based  on  scenarios  involving  the 
most  likely  and  worst-case  physical  security  breaches, 
aircraft  impact,  conventional  explosive  detonation,  and 
CBR  release  scenarios.  This  final  and  important 
measure  must  include  establishing  processes  and 
systems  for  coordinating  and  cooperating  with  local 
law  enforcement  and  emergency  response  personnel. 

To  facilitate  the  protection  of  prominent  commercial 
sites  and  facilities  against  terrorist  attack,  we  will  take 
action  to: 

Share  federal  building  security  standards  and  practices 
with  the  private  sector 

D  FI  S,  together  with  G  SA ,  N  I  ST  and  other  federal 
departments  and  agencies  will  develop  a  program 
to  share  federal  building  protection  standards, 


vulnerability  and  risk  assessment  methodologies, 
best  practices,  and  technology  solutions  (e.g. 
physical  barriers,  closed-circuit  television,  intrusion 
detection  devices,  CBR  detection  sensors,  and 
explosive  detection  systems)  with  commercial 
facility  owners  and  operators. 

F ad litate efficient  dissemination  of  threat  information 

D  FI  S,  in  concert  with  the  intelligence  and  law 
enforcement  communities,  will  explore  processes 
and  systems  to  enable  the  timely  dissemination  of 
threat  indications  and  warning  information  to 
commercial  facility  owners  and  operators. 

I  mplement  theH  omeland  Security  A  dvisory  System 

D  H  S  will  collaborate  with  commercial  facility 
owners  and  operators  to  align  the  FI  omeland 
Security  Advisory  System  with  specific  measures 
and  procedures  pertinent  to  commercial 
facility  security. 

E  xplore  options  for  incentives  for  theimplementation 

of  enhanced  design  features  or  security  measures 

D  H  S  will  explore  options  to  facilitate  incentives  for 
commercial  owners  and  operators  who  incorporate 
specific  security  and  safety  features  into  their  facility 
design,  or  who  adopt  specific  processes,  procedures, 
and  technologies  that  serve  to  deter,  prevent,  or 
mitigate  the  consequences  of  terrorist  attacks. 

I  mprove building  codes  for  privately  owned  fadlities 

NIST  will  develop  a  comprehensive  set  of  building 
codes  for  privately  owned  facilities  designed  to 
better  assure  structural  integrity,  minimize 
probability  of  collapse,  and  increase  resistance  to 
high-temperature  fires. 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  79 


80  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


CONCLUSION 


Protecting  our  county’s  critical  infrastructures  and 
key  assets  is  a  core  homeland  security  mission.  T  his 
Strategy  reaffirms  our  commitment  as  a  N  ation  to 
protect  our  critical  infrastructures  and  key  assets 
against  further  terrorist  attacks. 

As  we  begin  to  address  the  myriad  of  physical 
protection  challenges,  we  must  keep  in  mind  the 
complex  nature  of  the  infrastructures  and  assets  we  aim 
to  protect.  As  a  potential  target  set,  our  country's  crit¬ 
ical  infrastructures  and  key  assets  are  a  highly  diverse, 
interdependent  mix  of  facilities,  systems,  and  functions. 
G  overnment  owns  and  operates  some  of  them.  M  ost, 
however,  are  controlled  by  the  private  sector.  All  are 
vulnerable  in  some  way  to  the  terrorist  threat. 

T  hey  also  represent  a  true  "system  of  systems."  Failure 
in  one  asset  or  infrastructure  can  cascade  to  disruption 
or  failure  in  others,  and  the  combined  effect  could 
prompt  far-reaching  consequences  affecting  govern¬ 
ment,  the  economy,  public  health  and  safety,  national 


security,  and  public  confidence.  Asa  whole,  our 
protection  mindset  must  include  a  thorough 
appreciation  of  these  complexities  as  we  carry  out 
this  national  strategy  for  action. 

I  n  this  document  we  have  highlighted  the  diverse 
physical  protection  challenges  that  we  face  as  a  N  ation. 
We  have  laid  out  a  comprehensive  agenda  that  will 
allow  us  to  address  the  most  pressing  impediments 
to  our  physical  protection  based  upon  the  prudent 
management  of  threats,  vulnerabilities,  and  risks. 

This  is  only  the  beginning,  however,  of  a  long  and 
challenging  journey. 

As  we  begin,  we  must  also  keep  in  mind  the  nature  of 
the  adversary  we  now  face.  T  he  September  11  attacks  on 
the  World  Trade  Center  and  the  Pentagon  highlight  our 
national- level  physical  vulnerability  to  thethreat  posed 
by  a  highly  adaptive,  patient,  cunning,  and  flexible 
enemy.  T  he  attacks  also  demonstrate  the  extent  of  our 


THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  81 


enemy’s  determination  and  sophistication,  and  the 
lengths  to  which  terrorists  will  go  to  further  their  causes. 

We  no  longer  assume  that  terrorists  are  incapable  of 
undertaking  a  devastating  physical  attack  on  our 
homeland  and  infrastructure  base.  I  n  fact,  given  the 
creative  and  adaptive  nature  of  our  terrorist  adversaries, 
we  can  expect  future  strikes  to  be  even  more  sophisti¬ 
cated  in  terms  of  capability  and  synchronization. 

I  ronically,  the  very  nature  of  our  free  society  greatly 
enables  terrorist  operations  and  tactics,  while,  at  the 
same  time,  hinders  our  ability  to  predict  or  prevent 
terrorist  acts  or  mitigate  their  effects.  G  iven  these  real¬ 
ities,  the  imperative  to  implement  the  comprehensive 
national  physical  protection  strategy  outlined  in  this 
document  is  most  pressing. 

The  issues  and  enabling  initiatives  outlined  in  the 
Cross-Sector  Security  Priorities  chapter  of  this  document 
represent  important  near-term  national  priorities. They 
focus  on  impediments  to  physical  protection  that 
significantly  impact  multiple  key  sectors  of  our  govern¬ 
ment,  society,  and  economy.  Potential  solutions  to  the 
challenges  identified— such  as  information  sharing 
and  threat  indications  and  warning— are  high-leverage 
areas  that,  when  realized,  will  enhance  the  Nation’s 
overall  ability  to  protect  critical  infrastructures  and  key 
assets  across  the  board. 

These  action  areas,  which  include  the  prompt 
identification  and  protection  of  nationally  critical 
infrastructures  and  development  of  processes  and 
systems  to  properly  warn  and  protect  specifically 
threatened  assets  will  be  the  focus  of  the  federal 
government’s  near-term  critical  infrastructure  and  key 
asset  protection  effort.  Accordingly,  D  H  S  and  desig¬ 
nated  federal  lead  departments  and  agencies  will 
prepare  detailed  implementation  plans  to  support  the 
cross- sector  and  sector-specific  priorities  outlined  in 
this  document. 

As  we  work  to  refine  and  implement  our  priority 
protection  initiatives,  we  must  bear  in  mind  the 
guiding  principles  set  forth  in  this  document.  First  and 
foremost,  our  efforts  must  assure  public  health  and 
safety,  critical  services,  and  public  confidence  in  our 
government  and  economy.  T o  accomplish  this,  we  must 
establish  clear  roles  and  responsibilities,  accountability, 
and  coordinating  structures  and  processes  that  will 
govern  the  interaction  of  all  stakeholders. 


We  must  also  build  and  foster  a  partnership  among  all 
levels  of  government,  as  well  as  between  government 
and  the  private  sector.  This  public- private  partnership 
should  be  based  on  a  commitment  to  a  two-way 
communications  flow  and  the  timely  exchange  of 
information  relevant  to  critical  infrastructure  and  key 
asset  protection.  T  his  partnership  should  also  extend  to 
the  research,  development,  and  fielding  of  advanced 
technology  solutions  to  common  protection  problems. 
Collaborative  efforts  should  also  include  the  develop¬ 
ment  and  sharing  of  modeling  and  simulation 
capabilities  to  enable  public- private  sector  decision 
support  and  interdependency  analysis. 

T errorists  do  not  respect  international  boundaries  and 
are,  therefore,  not  restricted  by  them.  H  ence,  we  must 
extend  our  infrastructure  and  key  asset  protection 
partnership  to  include  our  M  exican  and  Canadian 
neighbors,  as  well  as  other  friendly  nations  around  the 
globe.  Finally,  as  we  take  action  to  overcome  the  major 
impediments  to  our  physical  protection,  we  must  take 
care  to  safeguard  the  fundamental  constitutional 
freedoms  that  have  long  been  the  hallmark  of  this 
great  N  ation. 

Federal  departments  and  agencies,  state  and  local 
government,  and  private  sector  owners  and  operators 
have  made  great  strides  to  enhance  the  security  of  the 
critical  infrastructures  and  key  assets  they  respectively 
control.  An  intense  cooperative  spirit  and  tremendous 
sense  of  urgency  have  characterized  our  national 
domestic  protection  environment  in  the  aftermath  of 
the  terrorist  strikes  of  September  11.  We  have  come  a 
long  way,  but  much  work  remains.  We  must  act 
together  now— through  aggressive  leadership  at  all 
levels  inside  and  outside  government— to  build  on 
this  shared  cooperative  spirit  and  carry  out  the 
implementing  activities  endorsed  in  this  document. 

0  ur  desired  end  state  is  the  protection  of  our  most 
nationally  critical  infrastructures  and  assets;  timely 
warning  and  protection  of  those  infrastructures  and 
assets  that  face  a  specific,  imminent  threat;  and  a 
collaborative  environment  in  which  all  stakeholders  can 
effectively  and  efficiently  carry  out  their  respective 
protection  responsibilities.  M  ake  no  mistake— the  road 
ahead  will  be  fraught  with  challenges.  Unified  in  our 
approach,  however,  we  will  overcome  these  challenges 
and  secure  our  critical  infrastructures  and  key  assets 
from  terrorist  exploitation. 


82  THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS 


ACRONYMS 


CBR: 

C hemical,  Biological,  or  Radiological 

DHS: 

D  epartment  of  H  omeland  Security 

DoD: 

D  epartment  of  D  efense 

DoE: 

D  epartment  of  E  nergy 

Dol: 

D  epartment  of  the  1  nterior 

Doj: 

Department  of  Justice 

DoS: 

D  epartment  of  State 

DoT: 

D  epartment  of  Transportation 

EMS: 

E  mergency  M  edical  Service 

EPA: 

Environmental  Protection  Agency 

FBIIC : 

Financial  and  Banking  Information 

1  nfrastructure  C  ommittee 

FCC : 

Federal  Communications  Commission 

FERC: 

Federal  Energy  Regulatory  Commission 

FS-ISAC : 

Financial  Services  1  nformati on  Sharing 
and  Analysis  Center 

GSA: 

General  Services  Administration 

HHS: 

D  epartment  of  FI  ealth  and  FI  uman 
Services 

H  VAC : 

FI  eating,  Ventilating,  and  Air 
Conditioning 

ISAC: 

Information  Sharing  and  Analysis C enter 

ISP: 

1  nternet  Service  Provider 

NERC: 

North  American  Electric  Reliability 
Council 

NGN: 

N  ext  G  eneration  N  etwork 

NIST: 

N  ational  1  nstitute  of  Science  and 
Technology 

NOC: 

N  etwork  0  peration  C  enter 

NRC: 

N  uclear  Regulatory  Commission 

OHS: 

Office  of  FI  omeland  Security 

PCIPB: 

President’s  C  ritical  1  nfrastructure 
Protection  Board 

PSTN: 

Public  Switched  Telecommunications 

N  etworks 

R&D: 

Research  and  Development 

USD  A: 

U  nited  States  D  epartment  of  A  griculture 

USPS: 

U  nited  States  Postal  Service 

THE  NATIONAL  STRATEGY  FOR  THE  PHYSICAL  PROTECTION  OF  CRITICAL  INFRASTRUCTURES  AND  KEY  ASSETS  83 


